Remote Code Execution in Discuz! DiscuzX 3.4 with WeChat Login
CVE-2018-20424
5.9MEDIUM
What is CVE-2018-20424?
The Discuz! DiscuzX 3.4 platform, when configured with WeChat login functionality, is susceptible to a vulnerability that allows remote attackers to execute an unauthorized request. By sending an ac=unbindmp request to the plugin.php file, attackers can delete the common_member_wechatmp data structure without any authentication, potentially compromising user data and system integrity.
