CVE-2023-0641

A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:employee_leaves_management_system_project:employee_leaves_management_system:1.0:*:*:*:*:*:*:*

History

07 Nov 2023, 04:01

Type Values Removed Values Added
CWE CWE-521

20 Oct 2023, 21:15

Type Values Removed Values Added
CWE CWE-521
Summary A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability. A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to weak password requirements. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-220021 was assigned to this vulnerability.

08 Feb 2023, 21:08

Type Values Removed Values Added
CPE cpe:2.3:a:employee_leaves_management_system_project:employee_leaves_management_system:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Employee Leaves Management System Project
Employee Leaves Management System Project employee Leaves Management System
References (MISC) https://vuldb.com/?ctiid.220021 - (MISC) https://vuldb.com/?ctiid.220021 - Third Party Advisory
References (MISC) https://github.com/ctflearner/Vulnerability/blob/main/Employee%20Leaves%20Management%20System/ELMS.md - (MISC) https://github.com/ctflearner/Vulnerability/blob/main/Employee%20Leaves%20Management%20System/ELMS.md - Exploit, Third Party Advisory
References (MISC) https://vuldb.com/?id.220021 - (MISC) https://vuldb.com/?id.220021 - Third Party Advisory

02 Feb 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-02 09:15

Updated : 2024-04-11 01:17


NVD link : CVE-2023-0641

Mitre link : CVE-2023-0641

CVE.ORG link : CVE-2023-0641


JSON object : View

Products Affected

employee_leaves_management_system_project

  • employee_leaves_management_system
CWE
CWE-521

Weak Password Requirements