PT-2022-23851 · Unknown · Bminusl Ihatetobudget
J-Gainsec
·
Published
2022-09-08
·
Updated
2023-08-08
·
CVE-2022-37163
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bminusl IHateToBudget version 1.5.7
Description
The issue is related to a weak password policy, which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper, making it easier for tools like hashcat to crack the hashes.
Recommendations
For Bminusl IHateToBudget version 1.5.7, consider implementing a stronger password policy and hashing user passwords with a salt or pepper to prevent unauthorized access. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bminusl Ihatetobudget