nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. This issue has been patched in version 12.122.2.
CVE ID: CVE-2023-49095
CVSS Base Severity: HIGH
CVSS Base Score: 8.6
Vendor: nexryai
Product: nexkey
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 25.76% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)