PT-2024-38487 · Unknown · Projectsend
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ProjectSend versions up to r1605
Description
A vulnerability was found in the Password Reset Token Handler component, specifically in the
generate random string function of the file includes/functions.php. This issue leads to insufficiently random values, which can be exploited remotely. The complexity of an attack is rather high, and the exploitability is difficult.Recommendations
For versions up to r1605, upgrade to version r1720 to address this issue. As a temporary workaround, consider restricting the use of the
generate random string function in the Password Reset Token Handler until the upgrade is applied.Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectsend