Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://github.com/janeczku/calibre-web/commit/49e4f540c9b204c7e39b3c27ceadecd83ed60e7e | patch |
https://huntr.dev/bounties/c3d5c647-7557-40a9-aee4-24dc14882781 | third party advisory exploit |