Skip to main content

Use of a Broken or Risky Cryptographic Algorithm

CVE-2024-51478

Severity High
Score 9.9/10

Summary

YesWiki is a PHP wiki system. In yeswiki/yeswiki versions prior to 4.4.5, a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allow it to be recovered and used to reset the password of any account.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • NONE
  • HIGH
  • LOW

CWE-327 - Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.

Advisory Timeline

  • Published