CVE Feed

    Dashboard / CVE / CVE-2023-53895

    CVE-2023-53895

    PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.

    Published:Dec 16, 2025
    Last Modified:Apr 7, 2026
    EPS:Dec 16, 2025
    EPSS Score:0.00576
    CVSS Score:9.8

    Affected Products

    Vendor
    Pimpmylog
    Product
    Pimpmylog
    Vendor
    Potsky
    Product
    Pimp My Log

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High