PT-2025-6884 · Pmweb · Pmweb
Ahmed8199
·
Published
2025-02-16
·
Updated
2025-02-16
·
CVE-2025-1341
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
PMWeb version 7.2.0
Description:
A problem has been detected in the Setting Handler component, leading to weak password requirements. The attack can be initiated remotely and has a high complexity, making exploitation difficult. The exploit has been made public and can be used. It is recommended to change the configuration settings to mitigate the issue. The vendor was contacted about this disclosure but did not respond.
Recommendations:
To resolve the issue in PMWeb version 7.2.0, change the configuration settings to enforce stronger password requirements. As a temporary workaround, consider restricting access to the Setting Handler component until a more permanent solution is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pmweb