CRITICAL🇵🇱 Wersja polska

CVE-2023-36993

CVSS 9.8v3.1pub. 2023-07-07upd. 2024-11-21

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Travianz Project Travianz

    APP
    Travianz Project
    8.3.38.3.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-36994CRITICAL9.8PL ✓same product

TravianZ – błędna kontrola dostępu umożliwiająca nadpisanie konfiguracji i wstrzyknięcie kodu PHP

CVE-2023-36992HIGH7.2same product

PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to ex...

CVE-2023-36995MEDIUM6.1same product

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Ad...