CVE-2018-20424: Input Validation
Published Dec 24, 2018
·Updated
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the commonmemberwechatmp data structure via an ac=unbindmp request to plugin.php.
Affected Software
1 affected component
Comsenz Discuzx=x3.4
Event History
Dec 24, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20424?
CVE-2018-20424 has a moderate severity rating as it allows unauthorized deletion of data.
2
How do I fix CVE-2018-20424?
To fix CVE-2018-20424, disable the WeChat login feature or apply the relevant security patches provided by Comsenz.
3
Who is affected by CVE-2018-20424?
CVE-2018-20424 affects users of Discuz! DiscuzX version 3.4 with WeChat login enabled.
4
What types of attacks can be executed using CVE-2018-20424?
Using CVE-2018-20424, attackers can remotely execute unbinding requests that could lead to data integrity issues.
5
Is there an official patch for CVE-2018-20424?
Yes, Comsenz has acknowledged the issue and recommended updates to address CVE-2018-20424.