{"id":"GHSA-f25v-x6vr-962g","summary":"Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password","details":"## Summary\n\nThe forced password-change flow, triggered when the stored password is still the default (`admin`), does not verify that the password submitted by the client actually matches the current password. Any non-empty value in `pheditor_password` is enough to reach the password-change form, and submitting `pheditor_new_password` / `pheditor_confirm_password` in the same request is enough to set an arbitrary new password and obtain an authenticated session — without ever proving knowledge of the current password.\n\n## Root Cause\n\n`pheditor.php` line 163:\n\n```php\nif (PASSWORD == hash('sha512', 'admin')) { // still default — force change prompt\n```\n\nThis checks whether the **stored** `PASSWORD` constant is still the default value. It does not check whether the **submitted** `pheditor_password` matches it. As a result, on any instance that hasn't changed the default password, the check passes regardless of what the client actually sends, and the subsequent password-change branch is reachable without authentication.\n\n## PoC\n\n```bash\nTARGET=\"https://victim.com/pheditor.php\"\n\n# Any non-empty value works here — password is never actually verified\ncurl -c /tmp/j.txt \\\n  -d 'pheditor_password=anything' \\\n  -d 'pheditor_new_password=attacker123' \\\n  -d 'pheditor_confirm_password=attacker123' \\\n  \"$TARGET\" -L -s -o /dev/null\n\n# Session is now authenticated as admin, with the password changed to attacker123\n```\n\n## Impact\n\nOn any instance where the default password has not yet been changed, an unauthenticated attacker can set an arbitrary new admin password and obtain a fully authenticated session, without knowing the current password. This is a complete authentication bypass, not merely \"default credentials in use\" — it holds even if the operator believes the instance is protected because the login form is present.\n\n## Remediation\n\nVerify the submitted password against the stored `PASSWORD` constant *before* entering the forced password-change branch, so the flow is reachable only by someone who actually knows the current password:\n\n```php\n$submitted_hash = hash('sha512', $_POST['pheditor_password']);\n\nif (PASSWORD == hash('sha512', 'admin') && $submitted_hash === PASSWORD) {\n    // proceed to forced password-change flow\n} else {\n    // treat as a normal login attempt (including rate-limiting)\n}\n```\n\n## Note on scope\n\nThe original report submitted alongside this finding also included two additional items:\n\n- **Unrestricted PHP upload** — addressed as intended behavior (Pheditor is a single-admin PHP file editor; PHP file creation/editing is core to its function, and pattern-restricting only the upload path doesn't reduce risk since the same result is reachable via the `save`/`newfile` action). Documented explicitly in the README's new Security Model section.\n- **Terminal allowlist bypass (`php -r ...`)** — a duplicate of a previously reported and already-patched issue (GHSA-g3hq-hphg-8fhh, fixed in v2.0.7).\n\nThis advisory has been scoped to the authentication bypass specifically, since it's a distinct root cause from both of those. Full responses to all three points are in the comments below.","modified":"2026-07-24T22:00:26.967609656Z","published":"2026-07-24T21:54:24Z","database_specific":{"github_reviewed_at":"2026-07-24T21:54:24Z","nvd_published_at":null,"cwe_ids":["CWE-1392"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pheditor/pheditor/security/advisories/GHSA-f25v-x6vr-962g"},{"type":"WEB","url":"https://github.com/pheditor/pheditor/commit/0978bcda644832b67357340e2f271e32d86fdf86"},{"type":"PACKAGE","url":"https://github.com/pheditor/pheditor"},{"type":"WEB","url":"https://github.com/pheditor/pheditor/releases/tag/2.0.8"}],"affected":[{"package":{"name":"pheditor/pheditor","ecosystem":"Packagist","purl":"pkg:composer/pheditor/pheditor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.8"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-f25v-x6vr-962g/GHSA-f25v-x6vr-962g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}