Magic Hash Authentication Bypass Vulnerability in Codiad 2.8.4

Magic Hash Authentication Bypass Vulnerability in Codiad 2.8.4

CVE-2020-23355 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.

Learn more about our User Device Pen Test.