← Back to CVE List

CVE-2020-23352

Published: 2021-01-27T16:15Z
Last Modified: 2024-11-21T05:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via magic hash values. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt