CVE detail
CVE-2019-5440 — CVE-2019-5440
Published 2019-05-28 · Modified 2026-06-17 · Vendor revive-adserver · Product revive_adserver · Source nvd
HIGH
severity
CVSS-derived band
0.0158
EPSS probability
exploitation probability, 30d
73.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() generates a password reset token that relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References