Impact
The vulnerability in yfexam‑exam version 2.0 results from deriving the JWT signing secret from the username and the current month instead of a random, server‑side key. This deterministic, low‑entropy secret enables an attacker who knows or can guess a username and the month to compute the secret by brute‑forcing potential values. With the secret in hand, the attacker can forge JSON Web Tokens that the application will accept, effectively allowing impersonation of any user account. The weakness is rooted in poor key generation and entropy, as reflected by the CWE reference CWE‑330.
Affected Systems
The affected product is yfexam‑exam version 2.0. No other vendors or version details are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the moderate‑to‑high severity range, while the EPSS score of less than 1% indicates a low probability of exploitation currently. The likely attack vector is remote HTTP endpoints that validate JWTs; the description indicates the attacker needs to know a username and month to derive the secret, and this is inferred because the advisory does not explicitly describe the method of attack. Exploitation would involve sending crafted tokens to the application, requiring no local privilege escalation. The vulnerability is not listed in the CISA KEV catalog, but its ability to forge tokens makes it a serious threat.
OpenCVE Enrichment