← Back

Discuzx

discuzx

Vendor: Comsenz • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.
1Comsenz
1Discuzx
Nov 21, 2024
Dec 24, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregist...Show more
Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).Show less