9.8

CVE-2021-27200

Exploit
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WowonderWowonder Version3.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.36% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://securityforeveryone.com/blog/wowonder-0-day-vulnerability-cve-2021-27200
Third Party Advisory
Exploit
https://www.exploit-db.com/exploits/49989
Third Party Advisory
Exploit
VDB Entry
https://www.wowonder.com
Product