5.5
CVSSv3

CVE-2023-35866

Published: 19/06/2023 Updated: 17/05/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

In KeePassXC up to and including 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

Vulnerable Product Search on Vulmon Subscribe to Product

keepassxc keepassxc

Github Repositories

Exploit Prediction Scoring System (EPSS) Usage of epss: -c string Sort data by CVE -d string Sort data by date -l int Number of results to limit -md Sort data by most dangerous Output of command: go run epssgo -l 3 Total: 205273 Offset: 0 Limit: 3 CVE ID: CVE-2023-35866 EPSS: 0000420000 Percentile: 000486000