Metrics
Affected Vendors & Products
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. | |
| Title | phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-16T21:39:32.603Z
Reserved: 2025-12-16T00:10:40.313Z
Link: CVE-2023-53894
Updated: 2025-12-16T21:39:29.416Z
Status : Received
Published: 2025-12-16T17:16:01.550
Modified: 2025-12-16T18:16:06.313
Link: CVE-2023-53894
No data.
OpenCVE Enrichment
No data.