Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/fac01e9f-e3e5-4985-94ad-59a76485f215 | third party advisory permissions required |
https://github.com/thorsten/phpmyfaq/commit/8beed2fca5b0b82c6ba866d0ffd286d0c1fbf596 | third party advisory patch |