CVE-2023-23498
published 2023-02-27CVE-2023-23498: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.3 and iPadOS 15.7.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3…
PriorityP410low3.3CVSS 3.1
AVLACLPRNUIRSUCNILAN
EPSS
0.23%
14.2th percentile
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.3 and iPadOS 15.7.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.7.3_and_ipados | — | — |
| apple | ios_16.3_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 16.3 | 16.3 |
| apple | ios_and_ipados | >= unspecified < 15.7 | 15.7 |
| apple | ipados | < 15.7.3 | 15.7.3 |
| apple | ipados | >= 16.0 < 16.3 | 16.3 |
| apple | iphone_os | < 15.7.3 | 15.7.3 |
| apple | iphone_os | >= 16.0 < 16.3 | 16.3 |
| apple | macos | >= 13.0 < 13.2 | 13.2 |
| apple | macos | >= unspecified < 13.2 | 13.2 |
| apple | macos_ventura | — | — |
| shopware | core | >= 6.7.0.0 < 6.7.6.1 | 6.7.6.1 |
| shopware | shopware | >= 6.7.0.0 < 6.7.6.1 | 6.7.6.1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
ghsa8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-23498: iOS 15.7.3 and iPadOS 15.7.3
vendor_apple·2023-01-23·CVSS 3.3
CVE-2023-23498 [LOW] CVE-2023-23498: iOS 15.7.3 and iPadOS 15.7.3
Apple Security Update: About the security content of iOS 15.7.3 and iPadOS 15.7.3
Product: iOS 15.7.3 and iPadOS
Version: 15.7.3
CVE: CVE-2023-23498
Component: Mail Exchange
Impact: The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account
Description: A logic issue was addressed with improved state management.
Apple
CVE-2023-23498: macOS Ventura 13.2
vendor_apple·2023-01-23·CVSS 3.3
CVE-2023-23498 [LOW] CVE-2023-23498: macOS Ventura 13.2
Apple Security Update: About the security content of macOS Ventura 13.2
Product: macOS Ventura
Version: 13.2
CVE: CVE-2023-23498
Component: Mail Drafts
Impact: The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account
Description: A logic issue was addressed with improved state management.
Apple
CVE-2023-23498: iOS 16.3 and iPadOS 16.3
vendor_apple·2023-01-23·CVSS 3.3
CVE-2023-23498 [LOW] CVE-2023-23498: iOS 16.3 and iPadOS 16.3
Apple Security Update: About the security content of iOS 16.3 and iPadOS 16.3
Product: iOS 16.3 and iPadOS
Version: 16.3
CVE: CVE-2023-23498
Component: Mail Drafts
Impact: The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account
Description: A logic issue was addressed with improved state management.
GHSA
Shopware Has Improper Control of Generation of Code in Twig rendered views
ghsa·2026-01-14·CVSS 8.8
CVE-2026-23498 [HIGH] CWE-94 Shopware Has Improper Control of Generation of Code in Twig rendered views
Shopware Has Improper Control of Generation of Code in Twig rendered views
### Impact
We fixed with [CVE-2023-2017](https://github.com/advisories/GHSA-7v2v-9rm4-7m8f) Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override
### Patches
Patched in 6.7.6.1
### Workarounds
Install the security plugin
GHSA
GHSA-59mr-vp8c-2fgm: A logic issue was addressed with improved state management
ghsa_unreviewed·2023-02-27
CVE-2023-23498 [LOW] GHSA-59mr-vp8c-2fgm: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 15.7.3 and iPadOS 15.7.3, iOS 16.3 and iPadOS 16.3. The quoted original message may be selected from the wrong email when forwarding an email from an Exchange account.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-27
Published