Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/0966043c-602f-463e-a6e5-9a1745f4fbfa | patch exploit third party advisory issue tracking |
https://github.com/polonel/trudesk/commit/13dd6c61fc85fa773b4065f075fceda563129c53 | third party advisory patch |