Skip to content
Noroxi

anuko records

12 published records for vendor anuko.

All records

12 records
  • In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    anuko · time trackerNov 16, 2020

  • Time Tracker has Blind SQL Injection Vulnerability in Reports

    CriticalCVSS 9.8No exploitEPSS 1%

    anuko · time trackerMay 12, 2023

  • SQL Injection Vulnerability in anuko timetracker

    CriticalCVSS 9.8No exploitEPSS 1%

    anuko · time trackerMay 15, 2023

  • SQL injection in anuko timetracker

    HighCVSS 8.8Proof of conceptEPSS 7%

    anuko · time trackerFeb 24, 2022

  • Predictable tokens used for password resets

    CriticalCVSS 9.1No exploitEPSS 2%

    anuko · time trackerMar 2, 2021

  • SQL injection vulnerability in anuko timetracker

    HighCVSS 8.8No exploitEPSS 1%

    anuko · time trackerDec 21, 2021

  • Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on

    HighCVSS 7.5Proof of conceptEPSS 6%

    anuko · time trackerNov 16, 2020

  • Cross site request forgery vulnerability

    HighCVSS 8.1No exploitEPSS 1%

    anuko · time trackerApr 13, 2021

  • CSV injection in Anuko Time Tracker

    HighCVSS 7.3Proof of conceptEPSS 4%

    anuko · time trackerOct 16, 2020

  • Reflected XSS vulnerability in time.php

    MediumCVSS 6.1No exploitEPSS 1%

    anuko · time trackerOct 13, 2021

  • Stored XSS vulnerability in anuko/timetracker

    MediumCVSS 5.4No exploitEPSS 1%

    anuko · time trackerFeb 24, 2022

  • Time Tracker has Stored XSS vulnerability in Week View plugin

    MediumCVSS 5.4No exploitEPSS 0%

    anuko · time trackerMay 9, 2023