CVE-2020-25987

HIGH

Monocms - Log Information Exposure

Title source: rule
STIX 2.1

Description

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://monocms.com/download

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 53.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
monocms/monocms 1.0
Published Oct 06, 2020
Tracked Since Feb 18, 2026