CVE-2020-14423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
18/06/2020
Last modified:
29/06/2020

Description

Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:convos:convos:*:*:*:*:*:*:*:* 4.20 (excluding)