← Vulnerability feed

Vulnerability record · CVE-2020-23355 · published 27 January 2021

CVE-2020-23355: Codiad vulnerability

CCodiad · Codiad

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.

7.5 CVSS 3.1 High EPSS 0.99% · top 39.1%
7.5CVSS 3.1 base score, v2 4.3
0.99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Codiad 2.8.4 /componetns/user/class.user.php:Authenticate() is vulnerable in magic hash authentication bypass. If encrypted or hash value for the passwords form certain formats of magic hash, e.g, 0e123, another hash value 0e234 something can successfully authenticate.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-23355 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19208Codiad code injection vulnerabilityCodiad Web IDE through 2.8.4 allows PHP Code injection.EPSS 19%9.8CVE-2018-14009Codiad improper input validation vulnerabilityCodiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.EPSS 38%9.8CVE-2017-11366Codiad os command injection vulnerabilitycomponents/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded …EPSS 7.5%8.8CVE-2020-14043Codiad cross-site request forgery vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Cross Side Request Forgery (CSRF) vulnerability was found in Codiad v1.7.8 and later. The request to down…EPSS 1.5%7.5CVE-2017-20178Codiad information exposure vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function s…EPSS 0.68%7.5CVE-2017-1000125Codiad incorrect permission assignment vulnerabilityCodiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.EPSS 0.92%7.2CVE-2020-14044Codiad server-side request forgery (ssrf) vulnerability** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** A Server-Side Request Forgery (SSRF) vulnerability was found in Codiad v1.7.8 and later. A user with admin …EPSS 3.2%7.2CVE-2018-19423Codiad unrestricted file upload vulnerabilityCodiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2020-23355), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.