Lucene search

K
osvGoogleOSV:GHSA-8FHH-HF9W-55P7
HistoryMay 24, 2022 - 5:40 p.m.

Codiad Vulnerable to PHP Magic Hash Vulnerability

2022-05-2417:40:24
Google
osv.dev
5

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

35.9%

Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234[something] can successfully authenticate.

CPENameOperatorVersion
codiad/codiadeq1.3.6

7.4 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

35.9%

Related for OSV:GHSA-8FHH-HF9W-55P7