Unknown · Projectsend · CVE-2024-7659
**Name of the Vulnerable Software and Affected Versions**
ProjectSend versions up to r1605
**Description**
A vulnerability was found in the Password Reset Token Handler component, specifically in the `generate random string` function of the file includes/functions.php. This issue leads to insufficiently random values, which can be exploited remotely. The complexity of an attack is rather high, and the exploitability is difficult.
**Recommendations**
For versions up to r1605, upgrade to version r1720 to address this issue. As a temporary workaround, consider restricting the use of the `generate random string` function in the Password Reset Token Handler until the upgrade is applied.