Description
The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.
Remediation
References
Related Vulnerabilities
XOOPS Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4851)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2017-1000014)
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2025-29793)
WordPress Plugin PowerPack Lite for Beaver Builder Cross-Site Scripting (1.3.0)