← Back to CVE List

CVE-2025-32352

Published: 2025-04-05T05:15Z
Last Modified: 2025-04-07T17:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt