Vulnerability Description
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Objectplanet | Opinio | < 7.23 |
Related Weaknesses (CWE)
References
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024Third Party Advisory
- https://www.objectplanet.com/opinio/changelog.htmlRelease Notes
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024Third Party Advisory
- https://www.objectplanet.com/opinio/changelog.htmlRelease Notes
FAQ
What is CVE-2023-4472?
CVE-2023-4472 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of...
How severe is CVE-2023-4472?
CVE-2023-4472 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-4472?
Check the references section above for vendor advisories and patch information. Affected products include: Objectplanet Opinio.