Количество 2
Количество 2
CVE-2020-23355
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.
GHSA-8fhh-hf9w-55p7
Codiad Vulnerable to PHP Magic Hash Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-23355 ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад | |
GHSA-8fhh-hf9w-55p7 Codiad Vulnerable to PHP Magic Hash Vulnerability | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу