CVE-2019-12396

CVE-2019-12396

An issue was discovered in Revive Adserver before 4.2.1. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() uses an insecure way to generate a password reset token. The token relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.

Source: CVE-2019-12396

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다