CVE-2023-40173

Source
https://cve.org/CVERecord?id=CVE-2023-40173
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-40173.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-40173
Aliases
  • GHSA-rfmv-7m7g-v628
Published
2023-08-18T21:47:17.987Z
Modified
2026-05-15T04:07:11.047207134Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Unsalted passwords in fobybus/social-media-skeleton
Details

Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not properly salt passwords leaving user passwords susceptible to cracking should an attacker gain access to hashed passwords. This issue has been addressed in version 1.0.5 and users are advised to upgrade. There are no known workarounds for this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40173.json"
}
References

Affected packages