CVE detail
CVE-2020-23352 — CVE-2020-23352
Published 2021-01-27 · Modified 2026-06-17 · Vendor zblogcn · Product z-blogphp · Source nvd
HIGH
severity
CVSS-derived band
0.0107
EPSS probability
exploitation probability, 30d
62.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via magic hash values.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References