Vulnerability DatabaseGHSA-6pq8-67pw-j6hw

GHSA-6pq8-67pw-j6hw
PHP vulnerability analysis and mitigation

Overview

A time-based information disclosure vulnerability was discovered in Flow's PersistedUsernamePasswordProvider component. The vulnerability was disclosed on November 1st, 2016, affecting all Flow versions before 2.3.16, 3.0.10, 3.1.7, 3.2.7, and 3.3.5. The security issue was assigned a moderate severity rating with a CVSS score of 5.3 (GitHub Advisory, Neos Blog).

Technical details

The vulnerability existed in the PersistedUsernamePasswordProvider component where password hashing was only performed when an account was found in the system. This implementation detail created a timing difference that could be exploited to determine the existence of user accounts. The vulnerability has been assigned a CVSS v3.1 base score of 5.3, with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, indicating network vector attack capability with low complexity and no required privileges or user interaction (GitHub Advisory).

Impact

The vulnerability could allow attackers to determine the existence of user accounts in the system through timing-based attacks. This information disclosure could potentially be used as a stepping stone for further targeted attacks. The impact was primarily limited to confidentiality with no direct effect on system integrity or availability (Neos Blog).

Exploitability

The vulnerability could be exploited remotely without requiring any special privileges or user interaction. The attack complexity is considered low, making it relatively straightforward to exploit the timing differences in the authentication process (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Flow versions 2.3.16, 3.0.10, 3.1.7, 3.2.7, and 3.3.5. The fix ensures that the provider always performs a password comparison when credentials are submitted, regardless of whether an account exists or not. Users are advised to update to these patched versions to protect against this vulnerability (Neos Blog).

Community reactions

The vulnerability was discovered by Kevin Fischer and Coresec Systems, who responsibly disclosed it to the Neos team. The Neos team subsequently developed and reviewed the fixes before releasing the patched versions (Neos Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management