Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/b3881a1f-2f1e-45cb-86f3-735f66e660e9 | exploit third party advisory patch |
https://github.com/thorsten/phpmyfaq/commit/00c04093c671607ee06cdfd670070809460f9547 | patch |