CVE-2016-5100
—CVSS 3.0
9.8 critical
EPSS
2%p79
Published
()
Modified
Description
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
- Vendors
- froxlor
- Products
- froxlor
- Weakness
- CWE-330
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.