CVE-2025-32352

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
Configurations

No configuration.

History

07 Apr 2025, 17:15

Type Values Removed Values Added
References () https://projectblack.io/blog/zendto-nday-vulnerabilities/ - () https://projectblack.io/blog/zendto-nday-vulnerabilities/ -

07 Apr 2025, 14:17

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de confusión de tipos en lib/NSSAuthenticator.php en ZendTo anterior a la v5.04-7 permite a atacantes remotos eludir la autenticación de usuarios con contraseñas almacenadas como hashes MD5 que pueden interpretarse como números. Una solución requiere migrar de MD5 a bcrypt.

05 Apr 2025, 06:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-843

05 Apr 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-05 05:15

Updated : 2025-04-07 17:15


NVD link : CVE-2025-32352

Mitre link : CVE-2025-32352

CVE.ORG link : CVE-2025-32352


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')