ZeroHour

CVE-2024-51478

PoC
CVSS 3.1
9.1 critical
EPSS
<1%p31
Published
()
Modified
Description

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.

Vendors
yeswiki
Products
yeswiki
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.