Use of a Broken or Risky Cryptographic Algorithm
CVE-2024-51478
Summary
YesWiki is a PHP wiki system. In yeswiki/yeswiki versions prior to 4.4.5, a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allow it to be recovered and used to reset the password of any account.
- LOW
- NETWORK
- LOW
- CHANGED
- NONE
- NONE
- HIGH
- LOW
CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.
References
Advisory Timeline
- Published