CVE-2020-27422
16.11.2020, 16:15
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.Enginsight
Vendor | Product | Version |
---|---|---|
anuko | time_tracker | 𝑥 ≤ 1.19.23.5311 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration