Description
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin SmokeSignal Cross-Site Scripting (1.2.6)
WordPress Plugin GoDaddy Email Marketing Cross-Site Request Forgery (1.1.2)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2025-59237)
Squid Out-of-bounds Write Vulnerability (CVE-2019-12521)
WordPress Plugin Theme Tweaker Cross-Site Request Forgery (5.20)