TROYANOSYVIRUS
Back to CVEs

CVE-2020-11035

HIGH
7.5

Description

In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published5/5/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

This product uses data from the NVD API but is not endorsed or certified by the NVD.