Description


Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.

Related CPE's


Could not find any relations

Weaknesses



CWE-916

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.9 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T22:17:30.640Z

20 hours ago

Last modified

2026-10-09T16:40:29.800Z

1 hour ago