GHSA-cjm4-2f5j-r6xxMediumCVSS 5.9

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows...

Published
November 14, 2023
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

🔗 References (4)