CVE-2024-51478

CRITICAL

Yeswiki < 4.4.5 - Broken Cryptographic Algorithm

Title source: rule
STIX 2.1

Description

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.

Scores

CVSS v3 9.9
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-327
Status published
Products (2)
yeswiki/yeswiki < 4.4.5
yeswiki/yeswiki 0 - 4.4.5Packagist
Published Oct 31, 2024
Tracked Since Feb 18, 2026