Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
References
Link Resource
https://hackerone.com/reports/1187820 Exploit Third Party Advisory
https://www.revive-adserver.com/security/revive-sa-2021-005/ Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2021-09-23T12:44:20

Updated: 2021-09-23T12:44:20

Reserved: 2021-01-06T00:00:00


Link: CVE-2021-22948

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-23T13:15:08.760

Modified: 2023-06-30T17:50:34.397


Link: CVE-2021-22948

JSON object: View

cve-icon Redhat Information

No data.