CVE-2023-4472

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:objectplanet:opinio:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-01 22:15

Updated : 2024-02-09 19:49


NVD link : CVE-2023-4472

Mitre link : CVE-2023-4472

CVE.ORG link : CVE-2023-4472


JSON object : View

Products Affected

objectplanet

  • opinio
CWE
CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)