admin/login.php in Stash 1.0.3 allows remote malicious users to bypass authentication and gain administrative access by setting a bsm cookie.
stash stash 1.0.3