CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.1. See the original NVD description below for full technical details.
CVE
CVE-2021-22948
Severity
HIGH
CVSS
7.1
EPSS
2.71%
Original NVD Description
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
Related CVEs
Other vulnerabilities affecting the same vendor(s)