Back to overview

CVE-2023-53894

CRITICAL
9.8
CVSS 3.1
Description
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

Metadata

CVE ID
CVE-2023-53894
State
PUBLISHED
Assigner
VulnCheck
Reserved
2025-12-16 00:10 UTC
Published
2025-12-16 17:03 UTC
Last updated
2026-04-07 14:07 UTC
Primary CWE
CWE-1390
Weak Authentication
Vendor / Product
Dulldusk / phpfm
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Dulldusk phpfm 1.7.9
Weakness (CWE)
CWESourceDescription
CWE-1390 cna Weak Authentication
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (3)
Back to overview