Description
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Published: 2021-06-11
Score: 9.8 Critical
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-13965 In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
History

No history.

Subscriptions

Wowonder Wowonder
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T20:40:47.462Z

Reserved: 2021-02-12T00:00:00.000Z

Link: CVE-2021-27200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-11T18:15:17.243

Modified: 2024-11-21T05:57:33.863

Link: CVE-2021-27200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses