Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcfw-jhvg-6wgg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via magic hash values.

Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via magic hash values.

EPSS

Процентиль: 47%
0.00242
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via magic hash values.

EPSS

Процентиль: 47%
0.00242
Низкий