Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/7fa956dd-f541-4dcd-987d-ba15caa6a886 | patch third party advisory exploit |
https://github.com/notrinos/notrinoserp/commit/e61e76b44c6a2b28a4a648a06ef34f65c376ec1e | third party advisory patch |