EXPOSURES › CVE-2023-43902
CVE-2023-43902
CRITICAL
DETAIL
SourceNVD · cve
Published2023-11-14
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-43902 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.