CVE-2021-23128

Vulnérabilités

CVE-2021-23128

An issue was discovered in Joomla!

CRITICAL Joomla CMS Source officielle

An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.

9.1 Critique · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDCRITICAL 9.1 (v3.1)
Produit
Joomla CMS
Corrigée dans
3.9.25
Publiée
04/03/2021
Modifiée
17/06/2026
  • 3.2.0 – 3.9.24
  • 3.2.0 – 3.9.25 (exclue)

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC