Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/54fb6d6a-6b39-45b6-b62a-930260ba484b | third party advisory exploit |
https://github.com/modoboa/modoboa/commit/130257c96a2392ada795785a91178e656e27015c | third party advisory patch |