CVE-2021-23126

MEDIUM5.3EPSS 0.01%

[20210301] - Core - Insecure randomness within 2FA secret generation

Published: 4/3/2025Modified: 5/20/2025

Description

An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of generating the 2FA secret.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (2)