ZeroHour

CVE-2016-5100

CVSS 3.0
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.

Vendors
froxlor
Products
froxlor
Weakness
CWE-330
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.