CVE-2020-27423: Anuko Time Tracker

High severity, CVSS 7.5. EPSS: 6.4% chance of exploitation in the next 30 days.

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

Affected products

  • Anuko Time Tracker: up to and including 1.19.23.5311

Published 2020-11-16. Last modified 2026-06-17.