PT-2026-73047 · Pkp-Lib · Pkp-Lib
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
pkp pkp-lib versions 3.3.0 through 3.5.0
Description
A weakness exists in the API Key Generation component within the
setData() function of the classes/user/form/APIProfileForm.php file. A remote attacker can manipulate the apiKey argument to cause insufficient entropy, which refers to a lack of randomness in the generated keys, potentially making them predictable. This attack is characterized by high complexity and is difficult to exploit.Recommendations
Apply patch 529b5df878e571ccc727647f7748eafc1466b041 for versions 3.3.0 through 3.5.0.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pkp-Lib