CVE-2023-21975 is a critical vulnerability (CVSS 9.0) affecting Oracle Application Express Customers Plugin versions 18.2-22.2, specifically within its User Account component. This easily exploitable flaw allows a low-privileged attacker with network access via HTTP to compromise the plugin, requiring user interaction but potentially impacting additional products. Successful exploitation can lead to a complete takeover of the Application Express Customers Plugin, resulting in high impacts to confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.2, <= 22.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.