CVE-2021-42216
CRITICALAnonAddy 0.8.5 - Inadequate Encryption Strength in VerificationController
Title source: llmDescription
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
References (3)
Core 3
Core References
Product x_refsource_misc
http://anonaddy.com
Patch, Third Party Advisory x_refsource_misc
https://github.com/anonaddy/anonaddy/blob/0478d9e8d364787f203113544123048a41f022c0/app/Http/Controllers/Auth/VerificationController.php#L67
Exploit, Patch, Third Party Advisory x_refsource_misc
https://huntr.dev/bounties/419f4e8a-ee15-4f80-bcbf-5c83513515dd
Scores
CVSS v3
9.8
EPSS
0.0140
EPSS Percentile
68.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-326
Status
published
Products (1)
anonaddy/anonaddy
0.8.5
Published
Dec 15, 2021
Tracked Since
Feb 18, 2026