{"id":"CVE-2021-22948","details":"Vulnerability in the generation of session IDs in revive-adserver \u003c 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.","modified":"2026-07-09T01:06:09.968222Z","published":"2021-09-23T13:15:08.760Z","references":[{"type":"FIX","url":"https://www.revive-adserver.com/security/revive-sa-2021-005/"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/1187820"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/revive-adserver/revive-adserver","events":[{"introduced":"0"},{"fixed":"c2d61b8bf32a5920d266432726af9032e8b33acb"},{"introduced":"e915c7be7cf86c6266e5f6fe06892cf8443e3081"},{"last_affected":"e915c7be7cf86c6266e5f6fe06892cf8443e3081"}],"database_specific":{"cpe":["cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*","cpe:2.3:a:revive-adserver:revive_adserver:5.3.0:rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"5.3.0"},{"introduced":"5.3.0-rc1"},{"last_affected":"5.3.0-rc1"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["5.3.0-rc1","v5.3.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22948.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}