CVE-2020-28642: Weak RNG
Published Nov 16, 2020
·Updated
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.
Affected Software
1 affected component
InfiniteWP InfiniteWP<3.1.12.3
Event History
Nov 16, 2020
CVE Published
via MITRE·01:19 AM
Data Sourced
via MITRE·01:19 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28642?
CVE-2020-28642 is considered a high severity vulnerability due to its potential for admin Account Takeover attacks.
2
How do I fix CVE-2020-28642?
To fix CVE-2020-28642, update InfiniteWP Admin Panel to version 3.1.12.3 or later.
3
Who is affected by CVE-2020-28642?
The vulnerability affects all users of InfiniteWP Admin Panel versions before 3.1.12.3.
4
What type of attack does CVE-2020-28642 facilitate?
CVE-2020-28642 facilitates remote attackers to conduct admin Account Takeover attacks.
5
What function is responsible for the weakness in CVE-2020-28642?
The weakness in CVE-2020-28642 stems from the resetPasswordSendMail function generating a weak password-reset code.