Predictable Token Generation in Piwigo Image Gallery Software by Piwigo
CVE-2016-3735
8.1HIGH
What is CVE-2016-3735?
Piwigo, an open-source image gallery software built in PHP, has a vulnerability that arises when specific criteria are not satisfied on a host. In these cases, Piwigo relies on the mt_rand function to create password reset tokens. Unfortunately, the output generated by mt_rand can be anticipated if an attacker is able to recover the seed value used for its generation. This flaw potentially allows an unauthenticated attacker to seize control of a user's account, provided they know the administrator's email address and can initiate a password reset request.
Affected Version(s)
Piwigo piwigo < 2.8.1