PHPGurukul Employee Leaves Management System changepassword.php weak password
Published Feb 2, 2023
9.1
CRITICALCVSS 3.1
EPSS 1.00%
Description
A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| PHP Gurukul | Employee Leaves Management System | n/a |
|
- 1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/ctflearner/Vulnerability/blob/main/Employee%20Leaves%20Management%20System/ELMS.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.220021 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.220021 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/ctflearner/Vulnerability/blob/main/Employee%20Leaves%20Management%20System/ELMS.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.220021 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.220021 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.