PT-2021-9149 · Epikur · Epikur

Published

2021-02-05

·

Updated

2021-07-21

·

CVE-2020-10538

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Epikur versions prior to 20.1.1
Description The issue concerns the storage of user passwords as MD5 hashes in the database, which can be brute-forced efficiently. The lack of salt in the hashing process makes it vulnerable to rainbow table attacks, further speeding up the potential breach.
Recommendations For versions prior to 20.1.1, update to version 20.1.1 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures such as multi-factor authentication to minimize the risk of exploitation. Restrict access to sensitive data and consider using a more secure password hashing algorithm that incorporates salting.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10538

Affected Products

Epikur