ZeroHour

CVE-2023-36993

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.

Vendors
travianz project
Products
travianz
Weakness
CWE-338
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.