CVE-2021-27200
CRITICALWoWonder 3.0.4 - Account Takeover via Weak Cryptographic Algorithm in recover.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-27200. PoCs published by securityforeveryone.com.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass in WoWonder Social Network Platform < 3.1 by predicting the password reset code due to weak cryptographic implementation. It brute-forces the code parameter using the server's timestamp and a predictable token range.
Description
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Exploits (1)
This exploit demonstrates an authentication bypass in WoWonder Social Network Platform < 3.1 by predicting the password reset code due to weak cryptographic implementation. It brute-forces the code parameter using the server's timestamp and a predictable token range.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H