CVE-2023-43902

Executive Summary

eMudhra emSigner v2.8.7 (v2.8.7) suffers an authentication bypass in its Forgot Your Password flow. An unauthenticated attacker can craft a password‑reset token and trigger a reset, thereby gaining access to any registered account—including administrators—without needing valid credentials. This flaw enables full account compromise and potential privilege escalation across the platform.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2023-11-14T05:15:08.833 - Last Modified: 2026-08-28T16:16:49.700

Original Description: Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.

"Accept challenges, so that you may feel the exhilaration of victory."

— George Patton
Source: NVD