Impact
A flaw in the password verification routine of dgtlmoon changedetection.io's Flask application allows an attacker to observe timing variations based on the supplied password. This side channel can reveal incremental password character matches, effectively enabling a remote attacker to reconstruct valid credentials. The weakness is a classic time‑variation side channel, identified as CWE‑208, and also involves improper hash validation that may expose sensitive information as defined in CWE‑203.
Affected Systems
The affected product is dgtlmoon changedetection.io, any deployed instance running version 0.60.7 or earlier. This includes all builds distributed under the open‑source package name changedetection.io, up to the specified version.
Risk and Exploitability
The vulnerability has a CVSS score of 6.3, indicating moderate severity. The exploit is known to exist and is publicly available, though finding a usable exploit requires high technical skill and careful timing measurements. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting the overall risk from widespread exploitation is moderate, but the potential impact warrants prompt attention. The attack vector is inferred to be remote, over the network, since the flaw exists in a publicly accessible authentication endpoint.
OpenCVE Enrichment