Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96v6-hrwg-p378

Опубликовано: 08 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Weak Password Requirements in Daybyday CRM

In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.

Пакеты

Наименование

bottelet/flarepoint

composer
Затронутые версииВерсия исправления

>= 1.1, < 2.2.1

2.2.1

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-521

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-521