Vulnerabilities > CVE-2018-15680 - Use of Password Hash With Insufficient Computational Effort vulnerability in Btiteam Xbtit 2.5.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |