CVE-2020-14423
18.06.2020, 14:15
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.Enginsight
Vendor | Product | Version |
---|---|---|
convos | convos | 𝑥 < 4.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References