CVE-2016-3735
Summary
| CVE | CVE-2016-3735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-28 20:15:00 UTC |
| Updated | 2023-11-07 02:32:00 UTC |
| Description | Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an unauthenticated attacker to take over an account providing they know an administrators email address in order to be able to request password reset. |
Risk And Classification
Problem Types: CWE-335
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Issues · Piwigo/Piwigo · GitHub | MISC | github.com | |
| Issues · Piwigo/Piwigo · GitHub | github.com | ||
| bug #470, use a dedicated lib to generate random bytes · Piwigo/Piwigo@f51ee90 · GitHub | MISC | github.com | |
| Whoops | piwigo.org | ||
| Whoops | MISC | piwigo.org | |
| Piwigo 2.8.1 | Release note | MITRE | piwigo.org | |
| increase randomness on generate_key · Issue #470 · Piwigo/Piwigo · GitHub | MITRE | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.