Intel

AIKIDO-2024-10403

prestashop/classic is vulnerable to Weak Password Requirements

Weak Password Requirements Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 4, 2024

30

Low Risk

This Affects:

phpprestashop/classic
2.0.0 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package have weak password requirements during the password reset process. prestashop/classic does not enforce strong password policies, allowing users to set easily guessable or insecure passwords. This weakness increases the risk of unauthorized access and account compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

prestashop/classic is vulnerable to Weak Password Requirements in versions 2.0.0 - 2.1.2.

How to fix this

Upgrade the prestashop/classic library to the patch version.