Impact
A weakness in YzmCMS's MD5 password handler allows manipulation of the password argument to produce a hash with insufficient computational effort. An attacker can launch this attack remotely, though it requires high complexity and is considered difficult to exploit. The effect is that attackers can more easily derive the original password, leading to potential unauthorized system access.
Affected Systems
YzmCMS versions up to and including 7.6 are affected. No patch has been released yet; the vendor plans a new release in March 2027 that will support gradual migration to stronger hashing algorithms.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Because the hash uses MD5 and is weak, this is inferred to make offline brute‑force easier, but the attack requires remote manipulation and is considered difficult, so the likelihood of exploitation is moderate.
OpenCVE Enrichment