Vulnerabilities
CVE-2023-53894 - phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability
CVE ID : CVE-2023-53894 Published : Dec. 16, 2025, 5:16 p.m. | 52 minutes ago Description : phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
PHP
Impact:
authentication bypass
Source: Telegram CVE Monitor