Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-526h-6368-hcf5

Опубликовано: 24 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

EPSS

Процентиль: 19%
0.00061
Низкий

8.3 High

CVSS3

Дефекты

CWE-521

Связанные уязвимости

CVSS3: 8.3
nvd
4 месяца назад

Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.

EPSS

Процентиль: 19%
0.00061
Низкий

8.3 High

CVSS3

Дефекты

CWE-521