Password Complexity Not Enforced On Password Change

Disclosed: 2018-03-03 13:55:25 By cosmopolitan_fi To owncloud
Low
Vulnerability Details
Hi! Owncloud does not enforce password complexity on password change, so it's possible to use passwords of any size or form. In example I can set my password to be "a" or "qwerty". __________________________________________________________________ How to reproduce: Change your password to something that does not match your required complexity. __________________________________________________________________ __________________________________________________________________ Proof Of Concept: Login with my dummy account account --> "[email protected]" password --> "q" __________________________________________________________________ Thanks! WdeM
Actions
View on HackerOne
Report Stats
  • Report ID: 276123
  • State: Closed
  • Substate: resolved
  • Upvotes: 9
Share this report