CVE-2020-27423 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 6.4% (pctl 94)
Patch early
A public exploit exists.
Description
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 6.44% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-307 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-11-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| anuko | time tracker |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality | 2020-12-02 |
References
→ the Explorer · watch your stack · NVD