CVE-2026-107829 PUBLISHED

Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql

Assigner: VulnCheck
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 08.10.2026

Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor banq
Product jivejdon
Versions Default: unaffected
  • affected from 0 to 5.0 (incl.)

Credits

  • Ikram-4 finder

References

Problem Types

  • Use of Password Hash With Insufficient Computational Effort CWE