← Back

CVE-2023-43902

nvd nist
Published: Nov 14, 2023Modified: Aug 28, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Affected (1)

Products: Emudhra: Emsigner
1 product
Emsigner
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.8.7

References (3)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.