ZeroHour

CVE-2023-26987

PoC ×2
CVSS 3.1
6.5 medium
EPSS
1%p63
Published
()
Modified
Description

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

Vendors
konga project
Products
konga
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.