CVE-2023-27172
Executive Summary
Xpand IT Write-back Manager v2.3.1 signs JWT tokens with weak secret keys, enabling attackers to brute‑force the key and forge tokens. This permits unauthorized authentication, data tampering, and potential escalation of privileges within the application. The vulnerability exposes sensitive operations to attackers without requiring initial compromise.
Authoritative CVE Metadata - CVSS Base Score: 9.1 (CRITICAL) - Published: 2023-12-20T01:15:07.233 - Last Modified: 2026-09-16T20:17:20.303
Original Description: Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
"Life is 10% what happens to you and 90% how you react to it."
— Charles Swindoll