PT-2022-22596 · Renato · Renato
J-Gainsec
·
Published
2022-08-04
·
Updated
2022-08-10
·
CVE-2022-35142
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Renato version 0.17.0
Description
The issue allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the
Search parameter. Additionally, Renato employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. There is also a cross-site scripting (XSS) vulnerability present in version 0.17.0.Recommendations
For version 0.17.0, update to version 0.17.1 to resolve the security issues, including the Denial of Service, weak password complexity, and cross-site scripting vulnerabilities. As a temporary workaround, consider restricting access to the
Search parameter to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Renato