Security Advisory

CVE-2016-5100

9.8
CRITICAL

Vulnerability Description

Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
Published Date February 13, 2017
Official Source NIST NVD Advisory