Vulnerability in the generation of session IDs in revive...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 9, 2023
Description
Published by the National Vulnerability Database
Sep 23, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jul 9, 2023
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
References