CVE-2021-4241 is a medium-severity vulnerability affecting phpservermon, specifically within the setUserLoggedIn function of src/psm/Service/User.php. It stems from the use of a predictable algorithm in a random number generator, leading to potential compromise of user sessions. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and potential for unauthorized information disclosure. While a public exploit has been disclosed and a patch is available, there is currently no evidence of active exploitation, nor are there any known Metasploit or Nuclei modules, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:phpservermonitor:php_server_monitor:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.