Bminusl IHateToBudget v1.5.7 employs a weak password...
Critical severity
Unreviewed
Published
Sep 9, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Sep 8, 2022
Published to the GitHub Advisory Database
Sep 9, 2022
Last updated
Jan 31, 2023
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.
References