Back

CRITICAL

Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token

Published Nov 14, 2023

Description

Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Nov 14, 2023
Updated Aug 28, 2026
Reserved Sep 25, 2023

CISA Vulnrichment

Updated Aug 28, 2026

NVD

Status Modified
Modified Aug 28, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Nov 14, 2023
Updated Aug 28, 2026

GitHub

No data