Sceawere
Vulnerability Detail
CVE-2026-105156UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YzmCMS Insufficient Password Hashing Complexity
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 5h ago
- Vendor
- n/a
- Product
- YzmCMS
- Attack Type
- Password Hash With Insufficient Computational Effort
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-04T15:16:30.050Z",
"pubdate": "2026-10-04T15:16:30.050Z",
"executiveSummary": "A critical weakness exists in the password hashing implementation of YzmCMS up to version 7.6, specifically within the MD5 Handler component.\nThe vulnerability, localized in the Password function within /common/function/system.func.php, involves the use of insufficient computational effort for hash generation, rendering stored credentials susceptible to rapid offline brute-force or rainbow table attacks.\nThis flaw allows remote, unauthenticated attackers to leverage the weak hashing scheme to recover cleartext passwords if the hash database is compromised.\nThe risk is significant due to the lack of modern cryptographic work factors, such as salts or adaptive stretching algorithms, providing inadequate protection against contemporary high-performance cracking hardware.\nWhile exploitation is characterized by high complexity and difficulty, the public availability of exploit information increases the threat level for existing deployments.\nThe vendor has confirmed that a backward-compatible gradual hash migration feature is scheduled for the March 2027 release, with interim mitigation documentation forthcoming.",
"technicalDetails": "The vulnerability originates from the implementation of the Password function in the /common/function/system.func.php file. The application relies on an inadequate hashing mechanism, categorized as an MD5 Handler, which fails to employ robust cryptographic standards required for secure password storage.\nRoot cause analysis indicates that the implementation lacks essential computational hardening, such as adaptive key stretching (e.g., Argon2, bcrypt, or scrypt) and per-user salt values. By utilizing a static or weakly derived MD5-based hashing process, the system produces hashes with high collision probability and minimal entropy, which significantly reduces the cost of reversal for an attacker.\nExploitation is conducted remotely. In a typical attack flow, an adversary who gains access to the database or credential storage—via secondary vulnerabilities such as SQL injection or unauthorized backups—can perform an offline analysis of the hashed credentials. Given the low computational cost associated with reversing MD5 hashes, an attacker can utilize specialized GPU clusters or distributed computing resources to recover cleartext credentials in an expedited timeframe.\nThe vulnerable component is identified as the MD5 Handler logic within YzmCMS version 7.6 and earlier releases. The attack surface is exposed via the pass argument handled by the affected function. Because the current implementation does not enforce an sufficient work factor, the resulting hash output is mathematically insufficient to defend against modern dictionary attacks or exhaustive search methodologies.\nPost-exploitation impact includes full account compromise, potentially allowing unauthorized administrative access if high-privileged accounts utilize the weak hashing mechanism. The absence of adaptive hashing means that even legitimate password updates on current versions do not provide increased security, as the underlying function logic remains constant until a formal software update is applied by the vendor.\nThe difficulty noted for exploitation likely refers to the prerequisite of obtaining the hash database; however, the presence of public exploit material suggests that the methodological barriers for attackers are diminishing. The lack of cryptographic salt implementation is a critical failure, as it permits the use of precomputed rainbow tables to resolve multiple user passwords simultaneously without requiring individual cracking attempts for each entry."
}