PT-2022-20394 · Unknown · B2Evolution
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
b2evolution versions prior to 7.2.3
Description
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password.
Recommendations
For versions prior to 7.2.3, update to a version that includes a fix for the bad randomness function used in password reset tokens.
As a temporary workaround, consider restricting access to the password reset functionality until a patch is available.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B2Evolution