PT-2024-24464 · Unknown · Lomag Warehouse Management
Published
2024-05-01
·
Updated
2025-09-19
·
CVE-2024-32213
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LoMag WareHouse Management application versions 1.0.20.120 and older
Description
The issue allows weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.
Recommendations
For versions 1.0.20.120 and older, consider updating the password policy to enforce stronger passwords with increased complexity and length.
As a temporary workaround, consider disabling the default hard-coded password feature until a more secure authentication mechanism is implemented.
Restrict access to sensitive areas of the application to minimize the risk of exploitation due to weak passwords.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lomag Warehouse Management