Authentication Bypass Vulnerability in Codiad by Codiad Team
CVE-2020-23355
7.5HIGH
What is CVE-2020-23355?
The Codiad 2.8.4 version exhibits a vulnerability where an attacker can bypass authentication due to issues in the magic hash authentication mechanism. Specifically, if the encrypted or hash values for certain password formats (e.g., 0e123) are utilized, it allows a malicious user to authenticate without proper credentials through manipulation of the hash values, such as 0e234. This vulnerability poses a significant risk as it may permit unauthorized access to sensitive functionalities within Codiad.