CVE-2020-28597

A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:epignosishq:efront:5.2.21:*:*:*:pro:*:*:*
cpe:2.3:a:epignosishq:efront:5.2.17:*:*:*:pro:*:*:*

Information

Published : 2021-03-03 10:15

Updated : 2022-08-31 12:21


NVD link : CVE-2020-28597

Mitre link : CVE-2020-28597


JSON object : View

CWE
CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

Advertisement

dedicated server usa

Products Affected

epignosishq

  • efront