An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared to a second MD5 hash, which is the same for every user (aka a "Backdoor Password" of 3p1kursupport). If the submitted password matches either one, access is granted.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.x41-dsec.de/lab/advisories/x41-2020-003-epikur | Exploit Third Party Advisory | 
| https://www.x41-dsec.de/lab/advisories/x41-2020-003-epikur | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2021-02-05 14:15
Updated : 2024-11-21 04:55
NVD link : CVE-2020-10539
Mitre link : CVE-2020-10539
CVE.ORG link : CVE-2020-10539
JSON object : View
Products Affected
                epikur
- epikur
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
