Feed/CVE-2020-27422
CVE-2020-27422CRITICALCVSS 9.8

CVE-2020-27422

Published Nov 16, 2020·Updated Jun 16, 2026

NVD Description

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free