ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-18220”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-18220
Published
2021-05-20
CVSS:
7.5
ShadowTrackr CVSS:
4.6
Summary:
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.