CVE-2026-86670 PUBLISHED

aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash

Assigner: VulDB
Reserved: 08.09.2026 Published: 08.09.2026 Updated: 08.09.2026

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.3

Product Status

Vendor aircheng-org
Product iWebShop-5
Versions
  • Version 5.0 is affected
  • Version 5.1 is affected
  • Version 5.2 is affected
  • Version 5.3 is affected
  • Version 5.4 is affected
  • Version 5.5 is affected
  • Version 5.6 is affected
  • Version 5.7 is affected
  • Version 5.8 is affected
  • Version 5.9 is affected
  • Version 5.10 is affected
  • Version 5.11 is affected
  • Version 5.12 is affected
  • Version 5.13 is affected
  • Version 5.14 is affected
  • Version 5.15 is affected

Credits

  • gscsd (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Password Hash With Insufficient Computational Effort CWE
  • Inadequate Encryption Strength CWE