PT-2023-27305 · Unknown · Social Media Skeleton

Zodiac0704

·

Published

2023-08-18

·

Updated

2023-08-23

·

CVE-2023-40173

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Social media skeleton versions prior to 1.0.5
Description The issue concerns a social media project implemented using php, css, javascript, and html. Prior to version 1.0.5, the project did not properly salt passwords, leaving user passwords susceptible to cracking should an attacker gain access to hashed passwords. This issue has been addressed in version 1.0.5.
Recommendations For versions prior to 1.0.5, upgrade to version 1.0.5 to address the issue. As a temporary workaround, consider implementing additional security measures to protect user passwords until the upgrade can be applied.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-40173
GHSA-RFMV-7M7G-V628

Affected Products

Social Media Skeleton