Skip to main content

CVE-2023-52077

8.9
HIGHCVSS v3.1 Base Score
0.14%
LOW RiskEPSS (33rd percentile)

Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as updating server settings, as well as compromise object storage and email server credentials. This issue has been patched in 12.23Q4.5.

Published: 12/27/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.9HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

EPSS Score (Exploitation Probability)

0.14%LOW Exploitation Risk
33rd percentile

This vulnerability has a 0.14% probability of being exploited in the next 30 days, ranking higher than 33% of all scored CVEs.

Related Vulnerabilities