Cryptographically Insecure Random Number Generator in TravianZ Allows Account Takeover

Cryptographically Insecure Random Number Generator in TravianZ Allows Account Takeover

CVE-2023-36993 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.

Learn more about our Web Application Penetration Testing UK.