PT-2022-11593 · Unknown · Phpservermon
Timz99
·
Published
2022-11-15
·
Updated
2023-07-18
·
CVE-2021-4241
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpservermon (affected versions not specified)
Description
A vulnerability was found in phpservermon, affecting the function
setUserLoggedIn of the file src/psm/Service/User.php. The manipulation leads to the use of a predictable algorithm in a random number generator. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, it is recommended to apply a patch, specifically bb10a5f3c68527c58073258cb12446782d223bc3. As a temporary workaround, consider disabling the
setUserLoggedIn function until a patch is available.Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpservermon