CVE-2020-23356
27.01.2021, 16:15
dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.Enginsight
Vendor | Product | Version |
---|---|---|
nibbleblog | nibbleblog | 3.7.1c:c |
𝑥
= Vulnerable software versions