Mend Vulnerability Database
What is a CVE vulnerability ID? What is a WS vulnerability ID? What is an MSC vulnerability ID?New vulnerability? Tell us about it!
We found results for “”
Date: January 5, 2022
OverviewThe “DaybydayCRM” enforces weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.
DetailsDaybydayCRM does not perform any password length validation when changing a password. When a user who has “Update a User” access set in “Roles and Permission” tries to update his password, weak passwords such as single characters like letter “a” are accepted by the application. An attacker could leverage this to guess the user’s password with little effort.
PoC DetailsLogin to the application as a user with privileges of “Update a User”.
go to settings and change your password. You are now able to change your password to anything including a 1 character password, without any minimum length or strength validation from the application’s side.
Affected Environmentsbottelet/flarepoint - 1.1 through 2.2.0
PreventionUpdate to 2.2.1 in "bottelet/flarepoint" package, 2.2.1 in "Bottelet/DaybydayCRM" repo.
Good to know:
|Attack Vector (AV):||Network|
|Attack Complexity (AC):||Low|
|Privileges Required (PR):||None|
|User Interaction (UI):||None|
|Access Vector (AV):||Network|
|Access Complexity (AC):||Low|