CVE-2024-51478

CRITICAL

YesWiki < 4.4.5 - Weak Password Reset Key Hashing via Hardcoded Salt

Title source: llm
STIX 2.1

Description

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.

Scores

CVSS v3 9.9
EPSS 0.0037
EPSS Percentile 28.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-327
Status published
Products (2)
yeswiki/yeswiki < 4.4.5
yeswiki/yeswiki 0 - 4.4.5Packagist
Published Oct 31, 2024
Tracked Since Feb 18, 2026