CVE-2021-31646: Critical severity gestsup vulnerability
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgotpwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31646?
CVE-2021-31646 is classified as a critical vulnerability due to its potential for remote account takeover.
How do I fix CVE-2021-31646?
To fix CVE-2021-31646, upgrade to Gestsup version 3.2.10 or later, which addresses the weak algorithm in the password recovery functionality.
What component of Gestsup is affected by CVE-2021-31646?
CVE-2021-31646 affects the forgot_pwd.php file used for password recovery.
What type of attack can exploit CVE-2021-31646?
CVE-2021-31646 can be exploited through a brute force attack on the password recovery token generation.
Is CVE-2021-31646 applicable to all versions of Gestsup?
CVE-2021-31646 is applicable to all versions of Gestsup prior to 3.2.10.