KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access to the local PC.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T10:49:08.940Z
Reserved: 2023-01-21T00:00:00
Link: CVE-2023-24055
Updated: 2024-08-02T10:49:08.940Z
Status : Modified
Published: 2023-01-22T04:15:11.560
Modified: 2024-11-21T07:47:20.550
Link: CVE-2023-24055
No data.
OpenCVE Enrichment
No data.
Weaknesses