CVE-2016-5100

CRITICAL

Froxlor < 0.9.35 - Predictable Password Reset Token via Weak PHP rand Function

Title source: llm
STIX 2.1

Description

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.

References (1)

Core 1
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/Froxlor/Froxlor/commit/da4ec3e1b591de96675817a009e26e05e848a6ba

Scores

CVSS v3 9.8
EPSS 0.0192
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-330
Status published
Products (2)
froxlor/froxlor < 0.9.34.2
froxlor/froxlor 0 - 0.9.35Packagist
Published Feb 13, 2017
Tracked Since Feb 18, 2026