A type confusion vulnerability in lib/NSSAuthenticator...
Moderate severity
Unreviewed
Published
Apr 5, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Apr 5, 2025
Published to the GitHub Advisory Database
Apr 5, 2025
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
References