Intel

AIKIDO-2025-10103

efipay/sdk-php-apis-efi is vulnerable to Use of a One-Way Hash without a Salt

Use of a One-Way Hash without a Salt Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 19, 2025

28

Low Risk

This Affects:

phpefipay/sdk-php-apis-efi
1.0.0 - 1.11.3
Fixed in 1.12.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by insecure hash generation without a unique salt, making it easier for attackers to crack hashes using precomputed tables. If an attacker gains access to the hashes, the lack of salt allows efficient brute-force attacks, such as rainbow table, that could potentially leak critical information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

efipay/sdk-php-apis-efi is vulnerable to Use of a One-Way Hash without a Salt in versions 1.0.0 - 1.11.3.

How to fix this

Upgrade the efipay/sdk-php-apis-efi library to the patch version.