Critical severity9.8NVD Advisory· Published Apr 26, 2021· Updated Jun 17, 2026
CVE-2021-31646
CVE-2021-31646
Description
Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Gestsup/Gestsupdescription
Patches
Vulnerability mechanics
References
3- gestsup.fr/index.phpnvdPatchVendor Advisory
- gestsup.fr/index.phpnvdPatchVendor Advisory
- dojo.maltem.ca/public/advisories/CVE-2021-31646.htmlnvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.