CVE-2021-42216
Critical · CVSS 9.8AnonAddy — Broken or Risky Cryptographic Algorithm (CWE-326)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-326
Description
A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php.
Search profile — drives PoC discovery
Symbols VerificationController.phpVerificationControllerapp/Http/Controllers/Auth/VerificationController.phpverifyhashsha1md5
Keywords CVE-2021-42216AnonAddyVerificationControllerbroken cryptographic algorithmCWE-326anonaddy 0.8.5weak hashemail verificationhuntr bounty
Versions: 0.8.5
References
- https://github.com/anonaddy/anonaddy/blob/0478d9e8d364787f203113544123048a41f022c0/app/Http/Controllers/Auth/VerificationController.php#L67
- https://huntr.dev/bounties/419f4e8a-ee15-4f80-bcbf-5c83513515dd
- http://anonaddy.com
- https://github.com/anonaddy/anonaddy/blob/0478d9e8d364787f203113544123048a41f022c0/app/Http/Controllers/Auth/VerificationController.php#L67
- https://huntr.dev/bounties/419f4e8a-ee15-4f80-bcbf-5c83513515dd
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z