5.5
CVSSv3

CVE-2023-24055

Published: 22/01/2023 Updated: 02/02/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8

Vulnerability Summary

** DISPUTED ** KeePass up to and including 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

keepass keepass

Github Repositories

Disclaimer This script is for educational and demonstration purposes only The author does not endorse or condone the use of this script for any criminal or malicious activities and it should only be used where explicitly allowed with proper permission This script should be used with caution, as it will alter the KeePass configuration file and delete any previously configured

KeePass-TriggerLess KeePass 2531 with removed ECAS Trigger System Remediating CVE-2023-24055

CVE-2023-24055 ** DISPUTED ** KeePass through 253 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC authe

CVE-2023-24055 PoC (KeePass 25x) Under discussion and analysis sourceforgenet/p/keepass/discussion/329220/thread/a146e5cf6b/ sourceforgenet/p/keepass/feature-requests/2773/ An attacker who has write access to the KeePass configuration file can modify it and inject malicious triggers, eg to obtain the cleartext passwords by adding an export trigger h

CVE-2023-24055 PoC (KeePass 25x) Under discussion and analysis sourceforgenet/p/keepass/discussion/329220/thread/a146e5cf6b/ sourceforgenet/p/keepass/feature-requests/2773/ An attacker who has write access to the KeePass configuration file can modify it and inject malicious triggers, eg to obtain the cleartext passwords by adding an export trigger h

PoC_CVE-2023-24055

CVE-2023-24055 POC and Scanner for CVE-2023-24055

keepass_CVE-2023-24055_yara_rule Contains a simple yara rule to hunt for possible compromised KeePass config files How-to Use a yara rule scanner, like yara, loki or thor-lite to scan systems with this rule The default location for the local KeePass config file is %APPDATA%\Roaming\KeePass\KeePassconfigxml

KeePass Enhanced Security Configuration Make your keepass more secure using the not very-well known KeePass enforced configuration file KeePass Enhanced Security Configuration Introduction General considerations Automatic installation Parameters Run Configuration file Sample file Screenshots More settings References FAQ Introduction KeePass is a great tool to store

Table of Contents 2023 year top total 30 2022 year top total 30 2021 year top total 30 2020 year top total 30 2019 year top total 30 2018 year top total 30 2017 year top total 30 2016 year top total 30 2015 year top total 30 2014 year top total 30 2023 star updated_at name url des 304 2023-03-18T21:10:14Z Windows_LPE_AFD_CVE-2023-21768 githubcom/chompie1337/Wi

Table of Contents 2023 year top total 30 2022 year top total 30 2021 year top total 30 2020 year top total 30 2019 year top total 30 2018 year top total 30 2017 year top total 30 2016 year top total 30 2015 year top total 30 2014 year top total 30 2023 star updated_at name url des 323 2023-03-23T01:27:35Z Windows_LPE_AFD_CVE-2023-21768 githubcom/chompie1337/Wi

Table of Contents 2023 year top total 30 2022 year top total 30 2021 year top total 30 2020 year top total 30 2019 year top total 30 2018 year top total 30 2017 year top total 30 2016 year top total 30 2015 year top total 30 2014 year top total 30 2013 year top total 30 2012 year top total 30 2011 year top total 30 2010 year top total 30 2009 year top total 30 2008 year top to