CVE-2022-45782
01.02.2023, 22:15
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
Vendor | Product | Version |
---|---|---|
dotcms | dotcms | 5.3.8.5 ≤ 𝑥 ≤ 5.3.8.15 |
dotcms | dotcms | 21.03 ≤ 𝑥 ≤ 21.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration