PT-2022-7862 · Piwigo · Piwigo

Published

2022-01-28

·

Updated

2022-11-07

·

CVE-2016-3735

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piwigo (affected versions not specified)
Description The issue affects Piwigo, an image gallery software written in PHP. When certain criteria are not met on a host, Piwigo defaults to using mt rand to generate password reset tokens. The output of mt rand can be predicted after recovering the seed used to generate it, allowing an unauthenticated attacker to take over an account if they know an administrator's email address and can request a password reset.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2016-3735

Affected Products

Piwigo