CVE-2023-36993
Summary
| CVE | CVE-2023-36993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-07 19:15:00 UTC |
| Updated | 2023-07-13 19:30:00 UTC |
| Description | The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts. |
Risk And Classification
Problem Types: CWE-338
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Travianz Project | Travianz | 8.3.3 | - | All | All |
| Application | Travianz Project | Travianz | 8.3.4 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TravianZ Hacked | MISC | bramdoessecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.