Impact
A flaw in the authentication storage component of aircheng-org iWebShop-5, specifically the controllers/admin.php file, allows an attacker to manipulate the Password argument and store credentials using a hash with insufficient computational work. The result is a password hash that is easily cracked with brute‑force tools, effectively eroding the confidentiality of user accounts. The vulnerability is exploitable remotely and was demonstrated publicly, indicating that remote actors can generate the weak hash without physical access.
Affected Systems
Aircheng-org iWebShop-5 versions up to 5.15 are affected. The vulnerability resides in the authentication storage functionality accessed via admin.php, and any instance of the product deployed without a patch or upgrade that adds stronger password hashing will be vulnerable.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate severity, while the EPSS score is not reported. The exploit is listed as having high complexity and is considered difficult but has already been published, meaning an attacker could exploit it if they discover the vulnerable endpoint. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote, requiring the ability to send crafted requests to the administrative interface. Exploitation would result in compromised administrative credentials and potential full control of the application.
OpenCVE Enrichment