CVE-2021-23128
An issue was discovered in Joomla!
CRITICAL
Joomla CMS
Source officielle
Description
An issue was discovered in Joomla! 3.2.0 through 3.9.24. The core shipped but unused randval implementation within FOF (FOFEncryptRandval) used an potential insecure implemetation. That has now been replaced with a call to 'random_bytes()' and its backport that is shipped within random_compat.
Sévérité
9.1
Critique · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.1 (v3.1) |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 3.9.25
- Publiée
- 04/03/2021
- Modifiée
- 17/06/2026
Versions concernées
- 3.2.0 – 3.9.24
- 3.2.0 – 3.9.25 (exclue)
Sources
- NVD CNA Joomla CVE-2021-23128 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC