VYPR

CWE-759

Use of a One-Way Hash without a Salt

VariantIncomplete

Description

The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (21)

page 2 of 2
  • CVE-2021-21253MedJan 21, 2021
    risk 0.00cvss 5.8epss 0.01

    OnlineVotingSystem is an open source project hosted on GitHub. OnlineVotingSystem before version 1.1.2 hashes user passwords without a salt, which is vulnerable to dictionary attacks. Therefore there is a threat of security breach in the voting system. Without a salt, it is much…