CVE-2023-43902

CRITICAL

emsigner 2.8.7 - Unauthenticated Account Access via Password Reset Token

Title source: llm
STIX 2.1

Description

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://secpro.llc/emsigner-cve-2/

Scores

CVSS v3 9.8
EPSS 0.0086
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
emsigner/emsigner 2.8.7
Published Nov 14, 2023
Tracked Since Feb 18, 2026