CVE-2023-53894 - phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability

CVE-2023-53894 - phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability

CVE ID : CVE-2023-53894 Published : Dec. 16, 2025, 5:16 p.m. | 52 minutes ago Description : phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
CRITICAL
Published
Dec. 16, 2025
Affected Product: PHP
Impact: authentication bypass

Source: Telegram CVE Monitor