Attackers Can Obtain Cleartext Passwords via XML Configuration File
CVE-2023-24055
Key Information:
Badges
What is CVE-2023-24055?
The vulnerability (CVE-2023-24055) in KeePass through version 2.53 allows attackers with write access to the XML configuration file to obtain cleartext passwords by adding an export trigger. The lead developer of KeePass disputes this as a problem, blaming the user for not keeping the environment secure. However, researchers and the security community argue that this vulnerability could be exploited by threat actors, and it is concerning that a proof-of-concept exploit has already been shared online. Users are recommended to implement additional security measures, but there is ongoing debate about the responsibility of KeePass for addressing this issue.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
KeePass disputes vulnerability allowing stealthy password theft
The development team behind the open-source password management software KeePass is disputing what is described as a newly found vulnerability that allows attackers to stealthily export the entire database in plain text.

Password-stealing “vulnerability” reported in KeePass – bug or feature?
It’s been a newsworthy few weeks for password managers – those handy utilities that help you come up with a different password for every website you use, and then to keep track of them all. At the end of...

Best of 2023: Another Password Manager Leak Bug: But KeePass Denies CVE
Two researchers report vulnerability in KeePass. But lead developer Dominik Reichl says it’s not a problem—and refuses to fix the flaw.
References
EPSS Score
35% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- đź“°
First article discovered by Security Boulevard
- 🟡
Public PoC available
- đź’°
Used in Ransomware
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved