Anuko Time Tracker v1.19.23.5311 lacks rate limit on the...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Nov 16, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
References