Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/a5d6c854-e158-49e9-bf40-bddc93dda7e6 | third party advisory exploit |
https://github.com/kromitgmbh/titra/commit/7f09078a2ab88c35f2375c5f67bd0336c0e6c7a1 | third party advisory patch |