Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8vg-3hf7-w2q5

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS downgrade attacks on the traffic from a mobile device, or through another means, they may be able to crack the hash in a reasonable amount of time and gain unauthorized access to the victim's account.

The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS downgrade attacks on the traffic from a mobile device, or through another means, they may be able to crack the hash in a reasonable amount of time and gain unauthorized access to the victim's account.

EPSS

Процентиль: 5%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hashes, either through exploiting cloud services, performing TLS downgrade attacks on the traffic from a mobile device, or through another means, they may be able to crack the hash in a reasonable amount of time and gain unauthorized access to the victim's account.

EPSS

Процентиль: 5%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-327