{"id":"CVE-2024-34914","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-34914","summary":"PHP Censor uses a weak hashing algorithm for the remember me key","details":"php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked \"remember me\" when logging in.","published":"2024-05-14T18:31:02Z","modified":"2024-05-19T02:24:47.080051Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"php-censor/php-censor","fixedVersion":"2.1.5"},{"ecosystem":"Packagist","name":"php-censor/php-censor","fixedVersion":"2.0.13"}],"fix":{"url":"https://github.com/php-censor/php-censor/commit/7b011d1b60f543e6ed814315a285cc80074d12e5","label":"php-censor/php-censor@7b011d1"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34914"},{"type":"WEB","url":"https://github.com/php-censor/php-censor/commit/7b011d1b60f543e6ed814315a285cc80074d12e5"},{"type":"WEB","url":"https://chmod744.super.site/redacted-vulnerability"},{"type":"PACKAGE","url":"https://github.com/php-censor/php-censor"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-05-19T02:24:47.080051Z"}}