← Retour aux CVEs
CVE-2021-27200
CRITICAL9.8
Description
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Details CVE
Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie6/11/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
wowonder:wowonder
Faiblesses (CWE)
CWE-330
References
https://www.exploit-db.com/exploits/49989(cve@mitre.org)
https://www.wowonder.com(cve@mitre.org)
https://securityforeveryone.com/blog/wowonder-0-day-vulnerability-cve-2021-27200(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/49989(af854a3a-2127-422b-91ae-364da2661108)
https://www.wowonder.com(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.