← Back to CVE List

CVE-2020-23356

Published: 2021-01-27T16:15Z
Last Modified: 2024-11-21T05:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt