A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://vuldb.com/?id.321507 | vdb entry |
https://vuldb.com/?ctiid.321507 | signature permissions required |
https://vuldb.com/?submit.635503 | third party advisory |
https://github.com/macrozheng/mall/issues/923 | issue tracking |