Description
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Weak password hashing rendering authentication vulnerable to brute force or credential compromise
Action: Immediate Patch
AI Analysis

Impact

A flaw in the authentication storage component of aircheng-org iWebShop-5, specifically the controllers/admin.php file, allows an attacker to manipulate the Password argument and store credentials using a hash with insufficient computational work. The result is a password hash that is easily cracked with brute‑force tools, effectively eroding the confidentiality of user accounts. The vulnerability is exploitable remotely and was demonstrated publicly, indicating that remote actors can generate the weak hash without physical access.

Affected Systems

Aircheng-org iWebShop-5 versions up to 5.15 are affected. The vulnerability resides in the authentication storage functionality accessed via admin.php, and any instance of the product deployed without a patch or upgrade that adds stronger password hashing will be vulnerable.

Risk and Exploitability

The CVSS score of 6.3 reflects moderate severity, while the EPSS score is not reported. The exploit is listed as having high complexity and is considered difficult but has already been published, meaning an attacker could exploit it if they discover the vulnerable endpoint. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote, requiring the ability to send crafted requests to the administrative interface. Exploitation would result in compromised administrative credentials and potential full control of the application.

Generated by OpenCVE AI on September 8, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a later iWebShop version that replaces the weak hashing routine with a secure algorithm such as PBKDF2, bcrypt, or Argon2, ensuring sufficient computational effort to hash passwords.
  • Enforce a robust password policy for all administrative accounts and enable multi‑factor authentication to add an extra layer of protection against credential compromise.
  • Restrict access to the admin interface by limiting permitted IP addresses, requiring VPN connection, or placing the service behind an authentication gateway to reduce the attack surface and expose the vulnerable endpoint only to trusted hosts.

Generated by OpenCVE AI on September 8, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
First Time appeared Aircheng-org
Aircheng-org iwebshop-5
Weaknesses CWE-326
CWE-916
CPEs cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
Vendors & Products Aircheng-org
Aircheng-org iwebshop-5
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Aircheng-org Iwebshop-5
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T18:19:56.188Z

Reserved: 2026-09-08T09:30:51.404Z

Link: CVE-2026-86670

cve-icon Vulnrichment

Updated: 2026-09-08T18:19:14.739Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:21:17.370

Modified: 2026-09-08T19:20:15.867

Link: CVE-2026-86670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:45:05Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength

  • CWE-916

    Use of Password Hash With Insufficient Computational Effort