Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.
The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.
Link | Tags |
---|---|
https://www.objectplanet.com/opinio/changelog.html | release notes |
https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0002.md | third party advisory |