Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://github.com/ikus060/rdiffweb/commit/233befc33bdc45d4838c773d5aed4408720504c5 | third party advisory patch |
https://huntr.dev/bounties/58eae29e-3619-449d-9bba-fdcbabcba5fe | third party advisory exploit |