YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yeswiki/yeswiki(Packagist) | 0 | 4.4.5 | N/A |
CVSS Metrics