Executive brief
Akinsoft TaskPano, a project and task management platform, contains a security flaw that fails to limit the number of login attempts. This allows an attacker to repeatedly guess passwords without being blocked, potentially leading to unauthorized access to corporate task data and project communications. Organizations using affected versions should update to version 1.06.06 or later to prevent account takeovers.
Technical details
Akinsoft TaskPano is vulnerable to CWE-307 (Improper Restriction of Excessive Authentication Attempts). The application fails to implement adequate rate limiting or account lockout mechanisms on its authentication interface. A remote, unauthenticated attacker can exploit this by automating a large number of login requests to guess user credentials. Successful exploitation results in an authentication bypass, granting the attacker access to the system with the privileges of the compromised account. The issue is fixed in version 1.06.06.
Affected products
- Akinsoft TaskPano from s1.06.04 before v1.06.06
Timeline
- 2025-09-04: advisory: Initial publication of CVE-2025-2411