Логотип exploitDog
bind:CVE-2021-31646
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-31646

Количество 2

Количество 2

nvd логотип

CVE-2021-31646

почти 5 лет назад

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-whcv-8x9m-33fh

больше 3 лет назад

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-31646

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

CVSS3: 9.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-whcv-8x9m-33fh

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу