Description
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.
Problem types
CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Product status
>= 3.0.0-alpha1, < 3.0.6
References
github.com/sulu/sulu/security/advisories/GHSA-7fv8-6pp7-6h85
github.com/sulu/sulu/releases/tag/2.6.23
github.com/sulu/sulu/releases/tag/3.0.6