The version of php installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2024-3096 advisory. In PHP version 8.1. before 8.1.28, 8.2. before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (x00), testing a blank string as the password via password_verify() will incorrectly return true. (CVE-2024-3096) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More