Description
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.
Remediation
References
Related Vulnerabilities
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2020-9664)
WordPress Plugin Author Manager Multiple Vulnerabilities (1.0)
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-5542)
WordPress Plugin WooCommerce Conversion Tracking Cross-Site Request Forgery (2.0.4)
WordPress Plugin W3 Total Cache Multiple Unspecified Vulnerabilities (0.9.5.1)