CVE-2023-43902
🔴 Łataj teraz
Błędna kontrola dostępu w EMSigner umożliwia atakującym dostęp do kont wszystkich użytkowników.
CVSS
9.8
EPSS
0.9%
Exploit
poc
Vendor
emudhra
Opis źródłowy (NVD)
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.9% |
| Opublikowano (NVD) | 2023-11-14 05:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 16:57:46 UTC |
Referencje
- https://secpro.llc/emsigner-cve-2/ (cve@mitre.org) [Exploit, Third Party Advisory]