CVE-2021-27200
EUVD-2021-1396511.06.2021, 18:15
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| wowonder | wowonder | 3.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References