CVE-2023-24055
MEDIUM 5.5EPSS 3.7%
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.
- CVSS v3.1
- 5.5 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS
- 3.69% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2023-01-22
- Updated
- 2024-08-02
Proof-of-concept exploits (6)
- deetl/CVE-2023-2405565★ · 2023-01-25
- julesbozouklian/PoC_CVE-2023-240551★ · 2023-01-31
- n3rada/Invoke-KeePassBackup3★ · 2023-11-08
- yosef0x01/CVE-2023-240550★ · 2023-02-04
- zwlsix/KeePass-CVE-2023-240551★ · 2023-02-14
- alt3kx/CVE-2023-24055_PoC