CVE-2023-36993
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jul 7, 2023
Updated: Jul 13, 2023
CWE ID 338
Summary
CVE-2023-36993 is a vulnerability affecting TravianZ versions 8.3.4 and 8.3.3. The issue lies in the use of a cryptographically insecure random number generator in the password reset function. An attacker can exploit this weakness to predict the parameters required to reset a user's password, ultimately gaining control over the affected accounts. This vulnerability poses a significant risk to user privacy and security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share