Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nordaaker Convos 安全特征问题漏洞
Vulnerability Description
Nordaaker Convos是挪威Nordaaker公司的一款基于Web浏览器的开源多用户聊天应用程序。 Nordaaker Convos 4.20之前版本中的Core/Settings.pm和Util.pm文件存在安全漏洞。攻击者可利用该漏洞影响密码重置和邀请。
CVSS Information
N/A
Vulnerability Type
N/A