Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/c7df088f-e355-45e6-9267-e41030dc6a32 | issue tracking third party advisory patch |
https://github.com/weseek/growi/commit/b584e2a47ee3c8ce1d8ef38238302825c015327e | third party advisory patch |