CVE-2023-26855

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
04/04/2023
Last modified:
13/02/2025

Description

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:churchcrm:churchcrm:4.5.3:*:*:*:*:*:*:*