Files
CVEs-PoC/2016/CVE-2016-6485.md
2025-09-29 21:09:30 +02:00

747 B

CVE-2016-6485

Description

The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.

POC

Reference

Github

No PoCs found on GitHub currently.