Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/FuncionarioControle.php follows the same pattern. SHA-256 is a general-purpose cryptographic hash built for speed, not password storage. Without a salt, identical passwords produce identical digests, making the entire hash database vulnerable to a single precomputed rainbow table lookup. This vulnerability is fixed in 3.7.3. | |
| Title | WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php | |
| Weaknesses | CWE-759 CWE-916 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T17:52:00.845Z
Reserved: 2026-05-08T16:58:28.896Z
Link: CVE-2026-45027
Updated: 2026-05-27T17:51:57.249Z
Status : Deferred
Published: 2026-05-27T17:16:40.227
Modified: 2026-05-27T19:49:48.143
Link: CVE-2026-45027
No data.
OpenCVE Enrichment
Updated: 2026-05-27T19:45:40Z