YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.
History

Thu, 31 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Yeswiki
Yeswiki yeswiki
CPEs cpe:2.3:a:yeswiki:yeswiki:-:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 31 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Description YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.
Title Use of a Broken or Risky Cryptographic Algorithm in YesWiki
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-31T16:15:46.811Z

Updated: 2024-10-31T16:51:13.578Z

Reserved: 2024-10-28T14:20:59.335Z

Link: CVE-2024-51478

cve-icon Vulnrichment

Updated: 2024-10-31T16:51:07.402Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-31T17:15:13.500

Modified: 2024-11-01T12:57:03.417

Link: CVE-2024-51478

cve-icon Redhat

No data.