CVE-2023-45794 - CVE House
Back to Database
Status published Medium CVE-2023-45794

A vulnerability has been identified in Mendix Applications using Mendix...

Vulnerability Description

A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications using Mendix 7 (All versions < V7.23.37), Mendix Applications using Mendix 8 (All versions < V8.18.27), Mendix Applications using Mendix 9 (All versions < V9.24.10). A capture-replay flaw in the platform could have an impact to apps built with the platform, if certain preconditions are met that depend on the app's model and access control design. This could allow authenticated attackers to access or modify objects without proper authorization, or escalate privileges in the context of the vulnerable app.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-45794

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Mendix Applications using Mendix 10, Mendix Applications using Mendix 7, Mendix Applications using Mendix 8, Mendix Applications using Mendix 9
Vulnerable Versions:
All versions < V10.4.0, All versions < V7.23.37, All versions < V8.18.27, All versions < V9.24.10

Timeline

Official Publish: November 14th, 2023
Last Modified: December 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.