Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Vulnerability Title
Sulu 加密问题漏洞
Vulnerability Description
Sulu是奥地利Sulu公司的一款可扩展的、基于PHP的开源内容管理系统上的Symfony框架。 Sulu 2.6.23之前版本和3.0.6之前版本存在加密问题漏洞,该漏洞源于密码重置令牌和API密钥生成使用弱加密哈希算法。
CVSS Information
N/A
Vulnerability Type
N/A