Описание
Codiad Vulnerable to PHP Magic Hash Vulnerability
Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234[something] can successfully authenticate.
Пакеты
Наименование
codiad/codiad
composer
Затронутые версииВерсия исправления
<= 2.8.4
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
около 5 лет назад
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.