CVE-2023-43902
Executive Summary
eMudhra emSigner v2.8.7 (v2.8.7) suffers an authentication bypass in its Forgot Your Password flow. An unauthenticated attacker can craft a password‑reset token and trigger a reset, thereby gaining access to any registered account—including administrators—without needing valid credentials. This flaw enables full account compromise and potential privilege escalation across the platform.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2023-11-14T05:15:08.833 - Last Modified: 2026-08-28T16:16:49.700
Original Description: Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
"Accept challenges, so that you may feel the exhilaration of victory."
— George Patton