Effectindex · Tripreporter · CVE-2023-31123
**Name of the Vulnerable Software and Affected Versions**
effectindex/tripreporter versions prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b
**Description**
The issue concerns an improper password verification vulnerability. This vulnerability allows any user with a password matching the password requirements to log in as any user, potentially leading to access to accounts and data loss of the user.
**Recommendations**
For versions prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, update to this commit or newer as soon as possible.
As a temporary workaround, someone running their own instance may apply the patch manually.