CVE-2025-32352 - ZendTo PHP Authentication Type Confusion Vulnerability
CVE ID : CVE-2025-32352
Published : April 5, 2025, 5:15 a.m. | 33 minutes ago
Description : A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 5, 2025, 5:15 a.m. | 33 minutes ago
Description : A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...