Логотип exploitDog
bind:CVE-2025-32352
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32352

Количество 2

Количество 2

nvd логотип

CVE-2025-32352

10 месяцев назад

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2xch-5969-phfh

10 месяцев назад

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32352

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-2xch-5969-phfh

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

CVSS3: 4.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу