Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-3754: fix: check for at least 8 characters for a password · thorsten/phpMyFAQ@d7a87d2

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE
#git#php

@@ -845,14 +845,14 @@ public function startInstall(array $setup = null): void

$esSetup = [];

}

// check loginname

// check login name

if (!isset($setup[‘loginname’])) {

$loginName = Filter::filterInput(INPUT_POST, 'loginname’, FILTER_UNSAFE_RAW);

} else {

$loginName = $setup[‘loginname’];

}

if (is_null($loginName)) {

echo '<p class="alert alert-danger"><strong>Error:</strong> Please add a loginname for your account.</p>’;

echo '<p class="alert alert-danger"><strong>Error:</strong> Please add a login name for your account.</p>’;

System::renderFooter(true);

}

@@ -863,8 +863,7 @@ public function startInstall(array $setup = null): void

$password = $setup[‘password’];

}

if (is_null($password)) {

echo '<p class="alert alert-danger"><strong>Error:</strong> Please add a password for the your ' .

'account.</p>’;

echo '<p class="alert alert-danger"><strong>Error:</strong> Please add a password for your account.</p>’;

System::renderFooter(true);

}

@@ -873,16 +872,18 @@ public function startInstall(array $setup = null): void

} else {

$passwordRetyped = $setup[‘password_retyped’];

}

if (is_null($passwordRetyped)) {

echo '<p class="alert alert-danger"><strong>Error:</strong> Please add a retyped password.</p>’;

System::renderFooter(true);

}

if (strlen($password) <= 5 || strlen($passwordRetyped) <= 5) {

if (strlen($password) <= 7 || strlen($passwordRetyped) <= 7) {

echo '<p class="alert alert-danger"><strong>Error:</strong> Your password and retyped password are too ' .

'short. Please set your password and your retyped password with a minimum of 6 characters.</p>’;

System::renderFooter(true);

}

if ($password != $passwordRetyped) {

echo '<p class="alert alert-danger"><strong>Error:</strong> Your password and retyped password are not ' .

'equal. Please check your password and your retyped password.</p>’;

Related news

GHSA-2rr3-rv49-p42f: phpMyFAQ contains Weak Password Requirements

phpMyFAQ prior to version 3.1.8 has Weak Password Requirements. Version 3.1.8 introduces an eight-character minimum password length.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907