Pimp My Log GitHub Repositoryproduct
https://github.com/potsky/PimpMyLog CVE-2023-53895
CRITICAL
PimpMyLog 1.7.14 Improper Access Control via Account Creation Endpoint
Record summary
CVE-2023-53895 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PimpMyLogBrowse Pimpmylog / PimpMyLogDefault status: unaffected | CVE List | 1.7.14 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPimpMyLog v1.7.14 - Improper access controlExploitDB exploitby thoughtfaultNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-53895 ExploitDB-51593exploit
https://www.exploit-db.com/exploits/51593 Pimp My Log Product Webpageproduct
https://www.pimpmylog.com/ VulnCheck Advisory: PimpMyLog 1.7.14 Improper Access Control via Account Creation EndpointThird-party advisory
https://www.vulncheck.com/advisories/pimpmylog-improper-access-control-via-account-creation-endpoint