CVE-2020-10539 Information
Jun 07, 2022
cve
Description
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that upon user login checks the submitted password against the user password’s MD5 hash stored in the database. It is also compared to a second MD5 hash which is the same for every user (aka a \Backdoor Password\ of 3p1kursupport). If the submitted password matches either one access is granted.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.x41-dsec.de/lab/advisories/x41-2020-003-epikur
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: