PT-2025-40851 · Mangati · Mangati Novosga
Marceloqz
·
Published
2025-10-06
·
Updated
2025-10-09
·
CVE-2025-11322
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mangati NovoSGA versions up to 2.2.12
Description
A weakness exists in Mangati NovoSGA up to version 2.2.12 related to weak password requirements during user creation. The issue is located in the User Creation Page component, specifically within the
/novosga.users/new file and involves manipulation of the Senha/Confirmação da senha argument. This can be exploited remotely, but requires a high level of complexity and is considered difficult to execute. The exploit has been published. The vendor was notified but did not respond.Recommendations
Versions prior to 2.2.12 should be updated.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mangati Novosga