PT-2022-15247 · Unknown · Daybyday Crm
Published
2022-01-05
·
Updated
2022-01-21
·
CVE-2022-22110
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Daybyday CRM versions 1.1 through 2.2.0
Description
The issue allows users with privileges to update their passwords to weak passwords, such as those with a length of a single character. This may enable an attacker to brute-force users' passwords with minimal to no computational effort.
Recommendations
For Daybyday CRM versions 1.1 through 2.2.0, consider implementing stronger password requirements to prevent the use of weak passwords, such as enforcing a minimum password length. As a temporary workaround, restrict users from updating their passwords to weak ones, such as those with a length of a single character, until a more robust password policy is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Daybyday Crm