Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h49-6g8c-82vj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.

EPSS

Процентиль: 80%
0.01334
Низкий

Связанные уязвимости

nvd
около 15 лет назад

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.

EPSS

Процентиль: 80%
0.01334
Низкий