CVE Database
/

CVE-2024-6890

Back to search

CVE-2024-6890

Published: Aug 7, 2024

Modified: Aug 8, 2024

PUBLISHED

Description

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

VendorProductVersions

Journyx

Journyx (jtime)

affected
11.5.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now