PT-2021-15383 · Joomla · Joomla!

Hanno Böck

·

Published

2021-03-04

·

Updated

2025-04-03

·

CVE-2021-23128

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Joomla! versions 3.2.0 through 3.9.24
Description An issue was discovered in the core shipped but unused randval implementation within FOF (FOFEncryptRandval), which used a potentially insecure implementation. This has been replaced with a call to random bytes() and its backport that is shipped within random compat.
Recommendations For Joomla! versions 3.2.0 through 3.9.24, update the randval implementation to use random bytes() to ensure secure random number generation.

Fix

Related Identifiers

BIT-JOOMLA-2021-23128
CVE-2021-23128

Affected Products

Joomla!