PT-2021-10887 · Webid · Webid
Peng-Hui
·
Published
2021-01-27
·
Updated
2021-02-02
·
CVE-2020-23359
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WeBid version 1.2.2
Description
The issue arises from a loose comparison used to check the identicalness of two passwords during registration in the admin/newuser.php file. This allows two non-identical passwords to bypass the check.
Recommendations
For WeBid version 1.2.2, consider modifying the password comparison function to use a strict comparison to ensure that only identical passwords are accepted during registration. As a temporary workaround, consider implementing additional validation checks on the
password and confirm password variables to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webid