ID:5845 - Exploit for Improper Authentication in FlexAir - CVE-2019-7666
Published: June 17, 2021
FlexAir
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the application allows improper authentication with the MD5 hash value of the password. A remote authenticated attacker can authenticate to the application without knowing the password of a specific username if previously obtained the database with all the MD5 hash passwords.