Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgj9-5874-x5mv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.

In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.

EPSS

Процентиль: 20%
0.00065
Низкий

Дефекты

CWE-521

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.

EPSS

Процентиль: 20%
0.00065
Низкий

Дефекты

CWE-521