Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234[something] can successfully authenticate.
{
"cwe_ids": [
"CWE-287",
"CWE-697"
],
"github_reviewed": true,
"github_reviewed_at": "2024-04-25T22:18:24Z",
"severity": "HIGH",
"nvd_published_at": "2021-01-27T16:15:00Z"
}