CVE-2023-45899: Idnovate Superuser

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.

Affected products

  • Idnovate Superuser: from 2.3.5, before 2.4.2 (fixed in 2.4.2)

Published 2023-10-31. Last modified 2026-06-17.