Impact
Admin3 through version 3.0.0 stores account passwords with a single-round MD5 hash using only the username as a salt. Because no key derivation function is employed, attackers who gain database access can extract plaintext passwords with minimal effort through offline dictionary or brute‑force attacks. This weakness permits credential disclosure and can lead to full account takeover of any user, impacting confidentiality and potentially granting unauthorized administrative access.
Affected Systems
The vulnerability affects the cjbi:admin3 product, specifically all releases up to and including 3.0.0. Users running these versions are susceptible if their database is compromised or leaked.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. While the EPSS score is not available, the CVE is not listed in the CISA KEV catalog. This flaw is exploitable only after an attacker obtains database files; it does not enable remote execution. Nonetheless, once the database is accessed, password recovery requires negligible computational resources, making credential compromise an immediate threat once the database is compromised.
OpenCVE Enrichment