ZeroHour

CVE-2023-49095

CVSS 3.1
7.5 high
EPSS
<1%p45
Published
()
Modified
Description

nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.

Vendors
nexryai
Products
nexkey
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.