Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qloapps
Qloapps qloapps |
|
| Vendors & Products |
Qloapps
Qloapps qloapps |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial. | |
| Title | QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php | |
| Weaknesses | CWE-916 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-03T14:12:34.812Z
Reserved: 2026-02-06T19:12:03.463Z
Link: CVE-2026-25861
Updated: 2026-06-03T14:12:14.377Z
Status : Deferred
Published: 2026-06-02T23:16:35.423
Modified: 2026-06-04T16:10:59.820
Link: CVE-2026-25861
No data.
OpenCVE Enrichment
Updated: 2026-06-03T10:54:27Z