描述
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.
AI分析AI驱动
受影响产品
churchcrmchurchcrm
4.5.3
参考资料
- https://github.com/ChurchCRM/CRM/issues/6449ExploitIssue TrackingThird Party Advisory
- https://github.com/ChurchCRM/CRM/issues/6449ExploitIssue TrackingThird Party Advisory