CVE-2023-47801
Description
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
In Passwordstate before 9811, Security Administrators can abuse API keys to read or delete private password records via the PasswordHistory endpoint.
Vulnerability
In Click Studios Passwordstate versions prior to 9811, users with the Security Administrator role can leverage the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. Additionally, the Copy/Move Password Record API Key can be used to copy or move private password records. This affects all builds before 9811.
Exploitation
An attacker must be an authenticated Security Administrator with access to either the System Wide API Key or the Copy/Move Password Record API Key. They can then craft API requests to the PasswordHistory endpoint to read or delete private password records, or use the Copy/Move API to copy or move private records. No further user interaction is required beyond the initial authentication.
Impact
Successful exploitation allows a Security Administrator to read or delete private password records that should be restricted, leading to unauthorized disclosure or loss of sensitive credentials. The attacker gains the ability to manipulate private password data beyond their intended privileges.
Mitigation
The vulnerability is fixed in Passwordstate version 9811. Users should upgrade to that version or later. No workaround is mentioned in the available references [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <9811
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.