VYPR

Pimpmylog

by Potsky

Source repositories

CVEs (1)

  • CVE-2023-53895CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden…