PT-2021-15381 · Joomla · Joomla!

Hanno Böck

·

Published

2021-03-04

·

Updated

2025-04-03

·

CVE-2021-23126

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.2.0 through 3.9.24
Description An issue was discovered in the usage of the insecure rand() function within the process of generating the 2FA secret.
Recommendations For versions 3.2.0 through 3.9.24, consider updating to a version that uses a secure random number generator for 2FA secret generation. As a temporary workaround, consider disabling the 2FA feature until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2021-23126
CVE-2021-23126

Affected Products

Joomla!