PT-2023-21223 · Unknown · Codeigniter Shield

Lonnieezell

·

Published

2023-03-13

·

Updated

2023-03-23

·

CVE-2023-27580

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CodeIgniter Shield versions 1.0.0-beta.3 and earlier
Description An improper implementation was found in the password storage process, making all hashed passwords stored in affected versions easier to crack than expected. If an attacker obtains the user's hashed password and the hashed password (SHA-384 hash without salt) from another source, they may easily crack the user's password.
Recommendations Upgrade to Shield v1.0.0-beta.4 or later to fix this issue. After upgrading, all users’ hashed passwords should be updated (saved to the database).

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-27580
GHSA-C5VJ-F36Q-P9VG

Affected Products

Codeigniter Shield