Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f7j-8hjh-h4v8

Опубликовано: 04 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3

Дефекты

CWE-330