5.3

CVE-2025-67168

Exploit
RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RitecmsRitecms Version3.1.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-916 Use of Password Hash With Insufficient Computational Effort

The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

https://github.com/handylulu/RiteCMS
Product
https://github.com/handylulu/RiteCMS/blob/master/cms/includes/functions.admin.inc.php
Product
https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67168
Third Party Advisory
Exploit