The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTravianz Project Travianz
APPTravianz Project8.3.38.3.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-36994CRITICAL9.8PL ✓same product
TravianZ – błędna kontrola dostępu umożliwiająca nadpisanie konfiguracji i wstrzyknięcie kodu PHP
CVE-2023-36992HIGH7.2same product
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to ex...
CVE-2023-36995MEDIUM6.1same product
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Ad...