I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-09-14 21:15
Updated : 2023-11-07 04:17
NVD link : CVE-2023-37756
Mitre link : CVE-2023-37756
CVE.ORG link : CVE-2023-37756
JSON object : View
Products Affected
i-doit
- i-doit
CWE
CWE-521
Weak Password Requirements