Security
Headlines
HeadlinesLatestCVEs

Headline

HealthForYou 1.11.1 / HealthCoach 2.9.2 Missing Password Policy

HealthForYou version 1.11.1 and HealthCoach version 2.9.2 are missing a server-side password policy. When creating an account or changing your password the mobile and web application both check the password against the password policy. But the API assumes that the given password is already checked therefore an attacker can intercept the HTTP request and change it to a weak password.

Packet Storm
#sql#web

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution