Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
redhat·CWE-640·Published 2020-02-04