Password Complexity Not Enforced On Password Change
Low
Vulnerability Details
Hi!
Owncloud does not enforce password complexity on password change, so it's possible to use passwords of any size or form.
In example I can set my password to be "a" or "qwerty".
__________________________________________________________________
How to reproduce:
Change your password to something that does not match your required complexity.
__________________________________________________________________
__________________________________________________________________
Proof Of Concept:
Login with my dummy account
account --> "[email protected]"
password --> "q"
__________________________________________________________________
Thanks!
WdeM
Actions
View on HackerOneReport Stats
- Report ID: 276123
- State: Closed
- Substate: resolved
- Upvotes: 9