Softwarex · Softwarex · CVE-2023-23911
**Name of the Vulnerable Software and Affected Versions**
SoftwareX versions prior to v6
**Description**
An improper access control issue exists that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.
**Recommendations**
For versions prior to v6, update to version v6 or later to resolve the issue. As a temporary workaround, consider restricting user permissions to change the group key of a chat room until a patch is available.