PT-2021-10885 · Codiad · Codiad

Peng-Hui

·

Published

2021-01-27

·

Updated

2022-05-24

·

CVE-2020-23355

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Codiad version 2.8.4
Description The issue concerns a magic hash authentication bypass vulnerability. It affects the Authenticate() function in the class.user.php file. Specifically, if the encrypted or hash value for passwords matches certain formats of magic hash, such as 0e123, another hash value like 0e234 can successfully authenticate. This allows for unauthorized access.
Recommendations For Codiad version 2.8.4, as a temporary workaround, consider disabling the Authenticate() function in the class.user.php file until a patch is available. Restrict access to the /componetns/user/class.user.php endpoint to minimize the risk of exploitation. Avoid using the 0e123 and 0e234 hash values in the affected authentication process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23355
GHSA-8FHH-HF9W-55P7

Affected Products

Codiad