PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
History

Wed, 17 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Pimpmylog
Pimpmylog pimpmylog
Vendors & Products Pimpmylog
Pimpmylog pimpmylog

Tue, 16 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 17:30:00 +0000


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
Title PimpMyLog 1.7.14 Improper Access Control via Account Creation Endpoint
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-16T17:06:14.418Z

Updated: 2025-12-16T21:44:30.969Z

Reserved: 2025-12-16T00:10:40.313Z

Link: CVE-2023-53895

cve-icon Vulnrichment

Updated: 2025-12-16T21:44:26.574Z

cve-icon NVD

Status : Received

Published: 2025-12-16T17:16:01.740

Modified: 2025-12-16T18:16:06.430

Link: CVE-2023-53895

cve-icon Redhat

No data.