High severity7.1NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026
CVE-2021-22948
CVE-2021-22948
Description
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<5.3.0+ 3 more
- (no CPE)range: <5.3.0
- (no CPE)
- cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*range: <5.3.0
- cpe:2.3:a:revive-adserver:revive_adserver:5.3.0:rc1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.revive-adserver.com/security/revive-sa-2021-005/nvdPatchVendor Advisory
- hackerone.com/reports/1187820nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.