CVE-2018-20423
HIGH
8,1
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
MEDIUM
6,8
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial
Description
AI Translation Available
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a 'disabled registration' setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0030
Percentile
0,5th
Updated
EPSS Score Trend (Last 90 Days)
Application
Discuzx by Comsenz
CPE Identifier
View Detailed Analysis
cpe:2.3:a:comsenz:discuzx:x3.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI
https://gitee.com/ComsenzDiscuz/DiscuzX/issues/IPRUI