CVSS Summary
Score | 10 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | Complete |
Integrity | Complete |
Availability | Complete |
Last revised:
The following refer to the generateAccessToken() function in library/OAuth2/ResponseType/AccessToken.php, and the generateAuthorizationCode() function in library/OAuth2/ResponseType/AuthorizationCode.php.
Current state: Reported
Score | 10 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | Complete |
Integrity | Complete |
Availability | Complete |
See the documentation:
http://www.php.net/manual/en/function.uniqid.php
http://www.php.net/manual/en/function.mt-rand.php
Upgrade to version 3.1.5 or later.
If this is not possible then ensure that you are using a recent version of php (at least 5.3), or disable the plugin.