Логотип exploitDog
bind:CVE-2025-54336
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-54336

Количество 2

Количество 2

nvd логотип

CVE-2025-54336

6 месяцев назад

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8h52-4p7x-v4mc

6 месяцев назад

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-54336

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-8h52-4p7x-v4mc

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу