← Back

CVE-2021-27913

nvd nist
Published: Aug 30, 2021Modified: Nov 21, 2024

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD

Description

The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature being one pseudorandomness, an attacker can take advantage of the cryptographically insecure nature of this function to enumerate session tokens for accounts that are not under his/her control This issue affects: Mautic Mautic versions prior to 3.3.4; versions prior to 4.0.0.

Affected (4)

Products: Acquia: Mautic
1 product
Mautic
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Acquia
Before 3.3.4
Version 4.0.0 alpha1
Version 4.0.0 beta
Version 4.0.0 rc

References (2)

Source: security@mautic.org
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory

Timeline

No history available yet.