PT-2022-7862 · Piwigo · Piwigo
Published
2022-01-28
·
Updated
2022-11-07
·
CVE-2016-3735
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Piwigo (affected versions not specified)
Description
The issue affects Piwigo, an image gallery software written in PHP. When certain criteria are not met on a host, Piwigo defaults to using
mt rand to generate password reset tokens. The output of mt rand can be predicted after recovering the seed used to generate it, allowing an unauthenticated attacker to take over an account if they know an administrator's email address and can request a password reset.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo