CVE detail
CVE-2023-53895 — CVE-2023-53895
Published 2025-12-16 · Modified 2026-06-17 · Vendor potsky · Product pimp_my_log · Source nvd
CRITICAL
severity
CVSS-derived band
0.0060
EPSS probability
exploitation probability, 30d
46.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References