Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jvmc-9qmp-g6pw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

EPSS

Процентиль: 93%
0.10185
Средний

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

EPSS

Процентиль: 93%
0.10185
Средний

Дефекты

CWE-613