PoC Index

CVE-2020-27422

CRITICAL 9.8EPSS 7.9%

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
7.86% chance of exploitation in the next 30 days, 94th percentile
Published
2020-11-16
Updated
2024-08-04

ExploitDB entries (1)

References

Related