Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
[20210301] - Core - Insecure randomness within 2FA secret generation
Vulnerability Description
An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Source Matters Joomla 安全特征问题漏洞
Vulnerability Description
Joomla是美国Open Source Matters团队的一套使用PHP和MySQL开发的开源、跨平台的内容管理系统(CMS)。 Joomla Core 存在安全特征问题漏洞,该漏洞源于在生成2FA密钥的过程中使用不安全的rand()函数。以下产品及版本受到影响:Joomla! 3.2.0 through 3.9.24.
CVSS Information
N/A
Vulnerability Type
N/A