CVE-2023-53895: PimpMyLog 1.7.14 Improper Access Control via Account Creation Endpoint
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.
Security readout for executives and security teams
Plain-English summary
CVE-2023-53895 affects PimpMyLog 1.7.14. The provided advisory says an unauthenticated remote attacker can create an admin account through a configuration endpoint, with potential access to logs and environmental variables. Treat exposed instances as urgent because logs often contain operational details, credentials, tokens, or sensitive business data.
Executive priority
Prioritize within the next remediation cycle, faster for internet-exposed instances. The business risk is unauthorized administrative access to a log-viewing system that may reveal sensitive operational data and support further compromise.
Technical view
The issue is CWE-285 improper access control in the account-creation/configuration path. The source bundle describes unauthenticated admin-account creation and username JavaScript injection used to hide a backdoor account. CVSS is 9.8, network-exploitable, low complexity, no privileges, no user interaction, with high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to organizations running PimpMyLog 1.7.14, especially if the application or configuration functions are reachable from untrusted networks. The provided affected list names only version 1.7.14 and marks other versions as unaffected by default.
Exploitation context
The bundle cites an ExploitDB entry, so public exploit information exists. CISA KEV status is false in the provided data, and no cited source here confirms active exploitation in the wild.
Researcher notes
Evidence is strong for critical severity and affected version from the provided CVE and advisory bundle. Evidence is incomplete for vendor patch status, exact fixed release, and real-world exploitation. Avoid assuming impact beyond PimpMyLog 1.7.14 unless additional vendor data confirms it.
Mitigation direction
Identify any PimpMyLog 1.7.14 deployments and prioritize them for review.
Check PimpMyLog and VulnCheck guidance for fixed versions or vendor-recommended remediation.
Restrict PimpMyLog access to trusted administrative networks until remediation is confirmed.
Remove or rotate secrets exposed through logs or environment variables if compromise is suspected.
Review and remove unauthorized administrator accounts.
Validation and detection
Confirm whether PimpMyLog is installed and record the exact version.
Verify the application is not reachable from the public internet.
Review administrator accounts for unexpected or hidden entries.
Inspect access and application logs for suspicious configuration or account activity.
Check whether sensitive logs or environment variables were accessible.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-285: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
5Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-285 · source CWE mapping
Improper Authorization
Improper Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.