In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
https://www.wowonder.com | product |
https://securityforeveryone.com/blog/wowonder-0-day-vulnerability-cve-2021-27200 | third party advisory exploit |
https://www.exploit-db.com/exploits/49989 | third party advisory vdb entry exploit |