Lucene search

K
osvGoogleOSV:CVE-2020-23361
HistoryJan 27, 2021 - 4:15 p.m.

CVE-2020-23361

2021-01-2716:15:13
Google
osv.dev
5
phplist
login bypass
vulnerability
cve-2020-23361
password hashes
type juggling

AI Score

7.2

Confidence

Low

EPSS

0.003

Percentile

70.0%

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

AI Score

7.2

Confidence

Low

EPSS

0.003

Percentile

70.0%

Related for OSV:CVE-2020-23361