GHSA-gp56-58fv-r42cCriticalCVSS 9.8

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows...

Published
November 14, 2023
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

🔗 References (4)