ZeroHour

CVE-2023-43902

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Vendors
emudhra
Products
emsigner
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.