Lucene search

K
osvGoogleOSV:CVE-2020-23355
HistoryJan 27, 2021 - 4:15 p.m.

CVE-2020-23355

2021-01-2716:15:12
Google
osv.dev
3

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

PRODUCT NOT SUPPORTED WHEN ASSIGNED Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

Related for OSV:CVE-2020-23355