We found results for “”
WS-2020-0069
Good to know:
Date: May 3, 2020
Insecure default secret key and IV allowing anyone to decrypt values
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Missing Encryption of Sensitive Data
CWE-311Top Fix
Upgrade Version
Upgrade to version nzo/url-encryptor-bundle - dev-fix-deprecation;nzo/url-encryptor-bundle - v4.2.2;nzo/url-encryptor-bundle - dev-master;nzo/url-encryptor-bundle - v4.4.0;nzo/url-encryptor-bundle - v5.1.0
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


