Weak Password Requirements in pimcore/pimcore


Reported on

Jul 28th 2021

1)Go to https://demo.pimcore.fun/en/account/register 2)Enter the username and password 3)Choose the password as 'a' and the account will be created.


We have contacted a member of the pimcore team and are waiting to hear back 2 years ago
Bernhard Rusch validated this vulnerability 2 years ago
sudheendra17 has been awarded the disclosure bounty
The fix bounty is now up for grabs
Bernhard Rusch marked this as fixed with commit d5f01f 2 years ago
Bernhard Rusch has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation