CVE-2023-49599
PHP vulnerability analysis and mitigation

Overview

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. The vulnerability (CVE-2023-49599) allows an attacker to gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user (Talos Report).

Technical details

The vulnerability exists in the salt generation process during installation, which uses PHP's uniqid() function that does not generate cryptographically secure values. The salt is used for AES-256-CBC encryption of password recovery codes. The encryption process uses a combination of the installation path as IV and the SHA256 hash of the salt as the secret key. The vulnerability stems from the predictable nature of uniqid() which generates values based on system time (Talos Report).

Impact

The vulnerability allows an attacker to forge valid password recovery codes for administrator accounts. By successfully exploiting this vulnerability, an attacker could reset an administrator's password without having access to the administrator's email, effectively gaining unauthorized administrative access to the system (Talos Report).

Mitigation and workarounds

The vulnerability has been patched in a vendor release on December 18, 2023. Users are advised to update to the patched version of WWBN AVideo (Talos Report).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23622HIGH8.7
  • PHPPHP
  • alextselegidis/easyappointments
NoNoJan 15, 2026
CVE-2026-23493HIGH8.6
  • PHPPHP
  • pimcore/pimcore
NoYesJan 15, 2026
CVE-2026-23496MEDIUM5.4
  • PHPPHP
  • pimcore/web2print-tools-bundle
NoYesJan 15, 2026
CVE-2026-23495MEDIUM4.3
  • PHPPHP
  • pimcore/admin-ui-classic-bundle
NoYesJan 15, 2026
CVE-2026-23494MEDIUM4.3
  • PHPPHP
  • pimcore/pimcore
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management