Lucene search

K
cvelistMitreCVELIST:CVE-2018-11554
HistoryJun 05, 2018 - 11:00 a.m.

CVE-2018-11554

2018-06-0511:00:00
mitre
www.cve.org

9.4 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.

9.4 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

Related for CVELIST:CVE-2018-11554