diff --git a/web/inc/main.php b/web/inc/main.php index dfa482a15e..e6ae4b915d 100644 --- a/web/inc/main.php +++ b/web/inc/main.php @@ -58,9 +58,10 @@ exit; } +// Generate CSRF Token if (isset($_SESSION['user'])) { - if(!isset($_SESSION['token'])){ - $token = uniqid(mt_rand(), true); + if (!isset($_SESSION['token'])){ + $token = bin2hex(file_get_contents('/dev/urandom', false, null, 0, 16)); $_SESSION['token'] = $token; } }