CVE-2020-28873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
17/03/2021
Last modified:
07/11/2023

Description

Fluxbb 1.5.11 is affected by a denial of service (DoS) vulnerability by sending an extremely long password via the user login form. When a long password is sent, the password hashing process will result in CPU and memory exhaustion on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fluxbb:fluxbb:1.5.11:*:*:*:*:*:*:*