The Code uses unsalted hashes of the passwords.
That way there is no random data added to the hashes and it is very easy to find identical hashes using
pre-computed lookup tables.

Using such a tool we found that the password admin123 has the same hash that is stored for the username admin.