Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-31646

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function), allowing a brute force attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-31646
  • Gestsup » Gestsup » Version: N/A
    cpe:2.3:a:gestsup:gestsup:-
  • Gestsup » Gestsup » Version: 3.1.15
    cpe:2.3:a:gestsup:gestsup:3.1.15
  • Gestsup » Gestsup » Version: 3.1.16
    cpe:2.3:a:gestsup:gestsup:3.1.16
  • Gestsup » Gestsup » Version: 3.1.17
    cpe:2.3:a:gestsup:gestsup:3.1.17
  • Gestsup » Gestsup » Version: 3.1.18
    cpe:2.3:a:gestsup:gestsup:3.1.18
  • Gestsup » Gestsup » Version: 3.1.19
    cpe:2.3:a:gestsup:gestsup:3.1.19
  • Gestsup » Gestsup » Version: 3.1.20
    cpe:2.3:a:gestsup:gestsup:3.1.20
  • Gestsup » Gestsup » Version: 3.1.21
    cpe:2.3:a:gestsup:gestsup:3.1.21
  • Gestsup » Gestsup » Version: 3.1.22
    cpe:2.3:a:gestsup:gestsup:3.1.22
  • Gestsup » Gestsup » Version: 3.1.23
    cpe:2.3:a:gestsup:gestsup:3.1.23
  • Gestsup » Gestsup » Version: 3.1.24
    cpe:2.3:a:gestsup:gestsup:3.1.24
  • Gestsup » Gestsup » Version: 3.1.25
    cpe:2.3:a:gestsup:gestsup:3.1.25
  • Gestsup » Gestsup » Version: 3.1.26
    cpe:2.3:a:gestsup:gestsup:3.1.26
  • Gestsup » Gestsup » Version: 3.1.27
    cpe:2.3:a:gestsup:gestsup:3.1.27
  • Gestsup » Gestsup » Version: 3.1.28
    cpe:2.3:a:gestsup:gestsup:3.1.28
  • Gestsup » Gestsup » Version: 3.1.29
    cpe:2.3:a:gestsup:gestsup:3.1.29
  • Gestsup » Gestsup » Version: 3.1.30
    cpe:2.3:a:gestsup:gestsup:3.1.30
  • Gestsup » Gestsup » Version: 3.1.31
    cpe:2.3:a:gestsup:gestsup:3.1.31
  • Gestsup » Gestsup » Version: 3.1.32
    cpe:2.3:a:gestsup:gestsup:3.1.32
  • Gestsup » Gestsup » Version: 3.1.33
    cpe:2.3:a:gestsup:gestsup:3.1.33
  • Gestsup » Gestsup » Version: 3.1.34
    cpe:2.3:a:gestsup:gestsup:3.1.34
  • Gestsup » Gestsup » Version: 3.1.35
    cpe:2.3:a:gestsup:gestsup:3.1.35
  • Gestsup » Gestsup » Version: 3.1.36
    cpe:2.3:a:gestsup:gestsup:3.1.36
  • Gestsup » Gestsup » Version: 3.1.37
    cpe:2.3:a:gestsup:gestsup:3.1.37
  • Gestsup » Gestsup » Version: 3.1.38
    cpe:2.3:a:gestsup:gestsup:3.1.38
  • Gestsup » Gestsup » Version: 3.1.39
    cpe:2.3:a:gestsup:gestsup:3.1.39
  • Gestsup » Gestsup » Version: 3.1.40
    cpe:2.3:a:gestsup:gestsup:3.1.40
  • Gestsup » Gestsup » Version: 3.1.41
    cpe:2.3:a:gestsup:gestsup:3.1.41
  • Gestsup » Gestsup » Version: 3.1.42
    cpe:2.3:a:gestsup:gestsup:3.1.42
  • Gestsup » Gestsup » Version: 3.1.43
    cpe:2.3:a:gestsup:gestsup:3.1.43
  • Gestsup » Gestsup » Version: 3.1.44
    cpe:2.3:a:gestsup:gestsup:3.1.44
  • Gestsup » Gestsup » Version: 3.1.45
    cpe:2.3:a:gestsup:gestsup:3.1.45
  • Gestsup » Gestsup » Version: 3.1.46
    cpe:2.3:a:gestsup:gestsup:3.1.46
  • Gestsup » Gestsup » Version: 3.1.47
    cpe:2.3:a:gestsup:gestsup:3.1.47
  • Gestsup » Gestsup » Version: 3.1.48
    cpe:2.3:a:gestsup:gestsup:3.1.48
  • Gestsup » Gestsup » Version: 3.1.49
    cpe:2.3:a:gestsup:gestsup:3.1.49
  • Gestsup » Gestsup » Version: 3.1.50
    cpe:2.3:a:gestsup:gestsup:3.1.50
  • Gestsup » Gestsup » Version: 3.2.0
    cpe:2.3:a:gestsup:gestsup:3.2.0
  • Gestsup » Gestsup » Version: 3.2.1
    cpe:2.3:a:gestsup:gestsup:3.2.1
  • Gestsup » Gestsup » Version: 3.2.2
    cpe:2.3:a:gestsup:gestsup:3.2.2
  • Gestsup » Gestsup » Version: 3.2.3
    cpe:2.3:a:gestsup:gestsup:3.2.3
  • Gestsup » Gestsup » Version: 3.2.4
    cpe:2.3:a:gestsup:gestsup:3.2.4
  • Gestsup » Gestsup » Version: 3.2.5
    cpe:2.3:a:gestsup:gestsup:3.2.5
  • Gestsup » Gestsup » Version: 3.2.6
    cpe:2.3:a:gestsup:gestsup:3.2.6
  • Gestsup » Gestsup » Version: 3.2.7
    cpe:2.3:a:gestsup:gestsup:3.2.7
  • Gestsup » Gestsup » Version: 3.2.8
    cpe:2.3:a:gestsup:gestsup:3.2.8
  • Gestsup » Gestsup » Version: 3.2.9
    cpe:2.3:a:gestsup:gestsup:3.2.9


Contact Us

Shodan ® - All rights reserved