CVE-2026-79575

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 15:18

Updated : 2026-09-09 16:04


NVD link : CVE-2026-79575

Mitre link : CVE-2026-79575

CVE.ORG link : CVE-2026-79575


JSON object : View

Products Affected

No product.

CWE
CWE-330

Use of Insufficiently Random Values