Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is described as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy | |
| First Time appeared |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| Weaknesses | CWE-203 CWE-208 |
|
| CPEs | cpe:2.3:a:dgtlmoon:changedetection.io:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dgtlmoon
Dgtlmoon changedetection.io |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-22T13:03:57.829Z
Reserved: 2026-09-22T05:02:51.234Z
Link: CVE-2026-95270
Updated: 2026-09-22T13:03:53.191Z
Status : Deferred
Published: 2026-09-22T12:17:14.557
Modified: 2026-09-22T19:04:55.677
Link: CVE-2026-95270
No data.
OpenCVE Enrichment
Updated: 2026-09-22T13:00:14Z