CVE-2018-20423: High severity discuz! vulnerability
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20423?
CVE-2018-20423 is classified as a medium severity vulnerability, allowing attackers to bypass registration controls.
How do I fix CVE-2018-20423?
To fix CVE-2018-20423, ensure that WeChat login is appropriately configured and disable the wxregister functionality if it is not needed.
Who is affected by CVE-2018-20423?
CVE-2018-20423 affects users of DiscuzX 3.4 with the WeChat login enabled.
What attack vector is used in CVE-2018-20423?
CVE-2018-20423 is exploited through the plugin.php component by manipulating the ac=wxregister query string.
What happens if I am vulnerable to CVE-2018-20423?
If vulnerable to CVE-2018-20423, an attacker could potentially register accounts bypassing the disabled registration settings.