CVE-2023-0744
CRITICALanswerdev/answer < 1.0.4 - Account Takeover via Improper Access Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0744. PoCs published by Eduardo Pérez-Malumbres Cervera.
AI-analyzed exploit summary This exploit demonstrates an account takeover vulnerability in Answerdev 1.0.3 by abusing the password reset functionality to generate a reset link for any email address without authentication.
Description
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Eduardo Pérez-Malumbres Cervera · pythonwebappsgo
https://www.exploit-db.com/exploits/51257
This exploit demonstrates an account takeover vulnerability in Answerdev 1.0.3 by abusing the password reset functionality to generate a reset link for any email address without authentication.
Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
Answerdev 1.0.3
No auth needed
Prerequisites:
Target URL · Victim email address
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory
https://huntr.dev/bounties/35a0e12f-1d54-4fc0-8779-6a4949b7c434
Exploit, Third Party Advisory
http://packetstormsecurity.com/files/171733/Answerdev-1.0.3-Account-Takeover.html
Scores
CVSS v3
9.8
EPSS
0.0852
EPSS Percentile
92.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (2)
answer/answer
< 1.0.4
answerdev/answer
0 - 1.0.4Go
Published
Feb 08, 2023
Tracked Since
Feb 18, 2026