CWE-836

Use of Password Hash Instead of Password for Authentication

High

Description

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

Potential Impact

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-836 vulnerabilities in your codebase.

Get Security Assessment