First published: Fri Jun 11 2021(Updated: )
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wowonder Wowonder | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27200 is a critical vulnerability in WoWonder 3.0.4 that allows remote attackers to take over any account due to a weak cryptographic algorithm in recover.php.
CVE-2021-27200 has a severity rating of 9.8, which is considered critical.
Attackers can exploit CVE-2021-27200 by predicting the code parameter from the time of day and taking over any account in WoWonder 3.0.4.
WoWonder version 3.0.4 is affected by CVE-2021-27200.
Yes, you can find more information about CVE-2021-27200 in the following references: [link1](https://securityforeveryone.com/blog/wowonder-0-day-vulnerability-cve-2021-27200), [link2](https://www.exploit-db.com/exploits/49989), [link3](https://www.wowonder.com).