CVE-2023-31123 is an improper password verification vulnerability affecting effectindex/tripreporter, including instances like subjective.report. This critical vulnerability (CVSS 9.1) allows any user with a password meeting requirements to log in as any other user, leading to unauthorized account access and potential data loss. The attack vector is network-based with low complexity, requiring no user interaction. While no active exploitation, public exploit code, or significant community discussion has been observed, affected instances should update to commit bd80ba833b9023d39ca22e29874296c8729dd53b or newer immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-04-30CPE matchmatch criteria | cpe:2.3:a:effectindex:tripreporter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.