Aller au contenu

Fiche vulnérabilité

CVE-2024-51478 : faille critique yeswiki yeswiki (CVSS 9.1)

Description

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
31 oct. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • yeswiki yeswiki

Références

Rechercher une autre vulnérabilité dans la base CVE