Critical severity9.1NVD Advisory· Published Dec 20, 2023· Updated Sep 16, 2026
CVE-2023-27172
CVE-2023-27172
Description
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:xpand-it:write-back_manager:2.3.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:xpand-it:write-back_manager:2.3.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: =2.3.1
Patches
Vulnerability mechanics
References
2- balwurk.github.io/CVE-2023-27172/nvdExploitThird Party Advisory
- ghostline.neocities.org/CVE-2023-27172/nvd
News mentions
0No linked articles in our index yet.