Vulnerabilities > CVE-2020-10538 - Use of Password Hash With Insufficient Computational Effort vulnerability in Epikur 20.1.0.1

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
epikur
CWE-916

Summary

An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.

Vulnerable Configurations

Part Description Count
Application
Epikur
2