peter bassill · operator
$ cve CVE-2020-27423 JSON

CVE-2020-27423 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 6.4% (pctl 94)

Patch early

A public exploit exists.

Description

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS6.44% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-307
On CISA KEVno
Public exploityes
Published2020-11-16
Last modified2026-06-17

Affected (1)

VendorProduct
anukotime tracker

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD