CVE-2021-27913 Information
Jun 07, 2022
cve
Description
The function mt_rand is used to generate session tokens this function is cryptographically flawed due to its nature being one pseudorandomness an attacker can take advantage of the cryptographically insecure nature of this function to enumerate session tokens for accounts that are not under his/her control This issue affects: Mautic Mautic versions prior to 3.3.4; versions prior to 4.0.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Reference
https://github.com/mautic/mautic/security/advisories/GHSA-x7g2-wrrp-r6h3
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
3.5
Share on: