Codiad 2.8.4 /componetns/user/class.user.php:Authenticate()
is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123
, another hash value 0e234[something]
can successfully authenticate.
{ "nvd_published_at": "2021-01-27T16:15:00Z", "cwe_ids": [ "CWE-287", "CWE-697" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-25T22:18:24Z" }