CVE-2023-53895
Unknown
Unknown - Not Provided
Improper Access Control in PimpMyLog 1.7.14 Enables Admin Account Creation
Publication date: 2025-12-16
Last updated on: 2025-12-16
Assigner: VulnCheck
Description
Description
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pimpmylog | pimpmylog | 1.7.14 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-285 | The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. |