CVE-2020-14423
EUVD-2020-656218.06.2020, 14:15
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| convos | convos | 𝑥 < 4.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References