PT-2022-15247 · Unknown · Daybyday Crm

Published

2022-01-05

·

Updated

2022-01-21

·

CVE-2022-22110

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Daybyday CRM versions 1.1 through 2.2.0
Description The issue allows users with privileges to update their passwords to weak passwords, such as those with a length of a single character. This may enable an attacker to brute-force users' passwords with minimal to no computational effort.
Recommendations For Daybyday CRM versions 1.1 through 2.2.0, consider implementing stronger password requirements to prevent the use of weak passwords, such as enforcing a minimum password length. As a temporary workaround, restrict users from updating their passwords to weak ones, such as those with a length of a single character, until a more robust password policy is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22110
GHSA-96V6-HRWG-P378

Affected Products

Daybyday Crm