Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/f4711d7f-1368-48ab-9bef-45f32e356c47 | patch third party advisory exploit |
https://github.com/thorsten/phpmyfaq/commit/d7a87d2646287828c70401ca8976ef531fbc77ea | third party advisory patch |