CVE-2025-32352

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
Configurations

No configuration.

History

No history.

Information

Published : 2025-04-05 05:15

Updated : 2025-04-07 17:15


NVD link : CVE-2025-32352

Mitre link : CVE-2025-32352

CVE.ORG link : CVE-2025-32352


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')