Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-11554
HistoryJun 05, 2018 - 11:29 a.m.

Default credentials

2018-06-0511:29:00
PRIOn knowledge base
www.prio-n.com
1

9.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.

CPENameOperatorVersion
yzmcmsge3.2
yzmcmsle3.7

9.2 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

Related for PRION:CVE-2018-11554