In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-06-11T17:40:45

Updated: 2021-06-11T17:40:45

Reserved: 2021-02-12T00:00:00


Link: CVE-2021-27200

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-06-11T18:15:17.243

Modified: 2022-07-12T17:42:04.277


Link: CVE-2021-27200

JSON object: View

cve-icon Redhat Information

No data.

CWE