
CVE@CVEnew
CVE-2026-94413 jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. At… https://www.cve.org/CVERecord?id=CVE-2026-94413
00000962
58.1K followersView on X
