PT-2026-96710 · Dgtlmoon · Changedetection.Io
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
dgtlmoon changedetection.io versions prior to 0.60.8
Description
A flaw in the Hash Comparison component allows for a remote attack. The
check password() function within the changedetectionio/flask app.py file is susceptible to manipulation of the Password argument, which results in an observable timing discrepancy. A timing discrepancy occurs when the time taken to execute a function varies based on the input provided, potentially allowing an attacker to deduce secret information by measuring these differences.Recommendations
Update dgtlmoon changedetection.io to version 0.60.8 or later.
As a temporary workaround, restrict access to the
check password() function to minimize the risk of exploitation.Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Changedetection.Io