Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash | |
| First Time appeared |
Aircheng-org
Aircheng-org iwebshop-5 |
|
| Weaknesses | CWE-326 CWE-916 |
|
| CPEs | cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aircheng-org
Aircheng-org iwebshop-5 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-08T18:19:56.188Z
Reserved: 2026-09-08T09:30:51.404Z
Link: CVE-2026-86670
No data.
Status : Deferred
Published: 2026-09-08T18:21:17.370
Modified: 2026-09-08T19:20:15.867
Link: CVE-2026-86670
No data.
OpenCVE Enrichment
Updated: 2026-09-08T18:45:05Z