Skip to content
COOEY

EXPOSURES › CVE-2023-43902

CVE-2023-43902

CRITICAL
DETAIL
SourceNVD · cve Published2023-11-14 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-43902 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.