Predictable Token Generation in Piwigo Image Gallery Software by Piwigo
CVE-2016-3735
What is CVE-2016-3735?
Piwigo, an open-source image gallery software built in PHP, has a vulnerability that arises when specific criteria are not satisfied on a host. In these cases, Piwigo relies on the mt_rand function to create password reset tokens. Unfortunately, the output generated by mt_rand can be anticipated if an attacker is able to recover the seed value used for its generation. This flaw potentially allows an unauthenticated attacker to seize control of a user's account, provided they know the administrator's email address and can initiate a password reset request.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Piwigo piwigo < 2.8.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
