Account Hijacking Risk in YzmCMS by YzmCMS Vendor
CVE-2018-11554
9.8CRITICAL
What is CVE-2018-11554?
The password reset functionality in YzmCMS versions 3.2 to 3.7 has a critical flaw that exposes user information through a discrepancy in responses. Additionally, the unusually long expiration time for verification codes heightens the risk of account compromise via brute-force methods. Remote attackers can exploit this vulnerability to hijack user accounts, thereby gaining unauthorized access and control.