Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://huntr.dev/bounties/85bfd18f-8d3b-4154-8b7b-1f8fcf704e28 | patch third party advisory exploit |
https://github.com/answerdev/answer/commit/7d23b17cdbbefcd2e7b5c3150f0b5ec908dc835f | patch |