Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27g5-f3jp-4f93

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.

Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.

EPSS

Процентиль: 67%
0.00545
Низкий

7.1 High

CVSS3

Дефекты

CWE-327
CWE-338
CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
почти 4 года назад

Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.

EPSS

Процентиль: 67%
0.00545
Низкий

7.1 High

CVSS3

Дефекты

CWE-327
CWE-338
CWE-79