Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOSLOCALSECRET value, affecting password resets and invitations.
{
"cpe": "cpe:2.3:a:convos:convos:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.20"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}