CVE-2020-14423: Convos
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.
Affected products
- Convos Convos: before 4.20 (fixed in 4.20)
Published 2020-06-18. Last modified 2026-06-17.