PT-2024-26247 · Unknown · Php-Censor

Published

2024-05-14

·

Updated

2024-07-08

·

CVE-2024-34914

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions php-censor versions 2.1.4
Description The issue allows attackers to bruteforce the remember key value, potentially gaining access to accounts that have checked "remember me" when logging in. This could lead to unauthorized access.
Recommendations For php-censor version 2.1.4, upgrade to version 2.1.5 to mitigate exposure. As a temporary workaround, consider disabling the "remember me" feature until the issue is resolved.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-34914
GHSA-FQW7-839J-HVXJ

Affected Products

Php-Censor