HIGH
CVSS 7
CVE-2024-0021: Weak Cryptography
Use of weak encryption algorithm (MD5) for passwords.
12/24/2024
Use of weak encryption algorithm (MD5) for passwords.
User session ID is not rotated after login.
Missing X-Frame-Options header allows clickjacking.
Unvalidated redirect URL parameter.
ReDoS vulnerability in email validation regex.