Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-10147 Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T14:00:49.118Z

Reserved: 2020-08-13T00:00:00

Link: CVE-2020-18220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-20T20:15:07.270

Modified: 2024-11-21T05:08:29.460

Link: CVE-2020-18220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.