Sulu
cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*
- <= 2.6.22
- <= 3.0.5
A vulnerability exists in Sulu, an open-source PHP content management system, prior to versions 2.6.23 and 3.0.6. The issue arises because the password reset token and API key generation processes utilize a weak cryptographic hash algorithm. This vulnerability has been addressed in the mentioned versions.
The use of a weak cryptographic hash algorithm for generating password reset tokens and API keys can lead to predictable token values, potentially allowing unauthorized users to reset passwords or impersonate users by generating valid API keys.
Users can upgrade to Sulu versions 2.6.23 or 3.0.6 to address this vulnerability. Instructions for upgrading are available in the Sulu documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.