PT-2022-11593 · Unknown · Phpservermon

Timz99

·

Published

2022-11-15

·

Updated

2023-07-18

·

CVE-2021-4241

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpservermon (affected versions not specified)
Description A vulnerability was found in phpservermon, affecting the function setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to the use of a predictable algorithm in a random number generator. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply a patch, specifically bb10a5f3c68527c58073258cb12446782d223bc3. As a temporary workaround, consider disabling the setUserLoggedIn function until a patch is available.

Exploit

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2021-4241
GHSA-HC4J-7MQG-CXJJ

Affected Products

Phpservermon