Password Hashing Vulnerability in ChurchCRM Version 4.5.3
CVE-2023-26855
7.5HIGH
What is CVE-2023-26855?
In ChurchCRM version 4.5.3, the implementation of the hashing algorithm employs a non-random salt value. This vulnerability exposes the system to potential password-cracking attacks, allowing attackers to leverage precomputed hash tables or dictionary attacks to decipher hashed passwords, thereby compromising user accounts.