CVE-2018-20422: High severity discuz! vulnerability
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#commonmemberwechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20422?
CVE-2018-20422 is classified as a high severity vulnerability due to its potential for unauthorized access to user accounts.
How do I fix CVE-2018-20422?
To fix CVE-2018-20422, update to the latest version of Discuz! that addresses the WeChat login vulnerability.
What systems are affected by CVE-2018-20422?
CVE-2018-20422 affects DiscuzX version 3.4 when WeChat login functionality is enabled.
What kind of attack does CVE-2018-20422 allow?
CVE-2018-20422 allows remote attackers to bypass authentication and gain unauthorized login access to user accounts.
Is user data at risk due to CVE-2018-20422?
Yes, CVE-2018-20422 poses a risk to user data as attackers can potentially access accounts without authorization.