PoC Index

CVE-2021-27913

LOW 3.5EPSS 0.5%

The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature being one pseudorandomness, an attacker can take advantage of the cryptographically insecure nature of this function to enumerate session tokens for accounts that are not under his/her control This issue affects: Mautic Mautic versions prior to 3.3.4; versions prior to 4.0.0.

CVSS v3.1
3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS v3.1
3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CVSS v3.1
3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS
0.46% chance of exploitation in the next 30 days, 38th percentile
Published
2021-08-30
Updated
2024-09-16

Proof-of-concept exploits (1)

References

Related