Loading HuntDB...

Null Password - Setting a new password doesn't check for empty spaces

Low
W
Weblate
Submitted None
Reported by footstep

Vulnerability Details

Technical details and impact analysis

Weak Cryptography for Passwords
Hi Again! As seen your website at https://demo.weblate.org/accounts/password/ >Your password can't be too similar to your other personal information. >Your password must contain at least 6 characters. >Your password can't be a commonly used password. >Your password can't be entirely numeric. I found that it is possible to create a password with `empty spaces`, not useful anyway but renders the password security weak. ##Reproduction Steps - Create a new account - Load the link sent to your mail - Now, set password to six spaces (tapping the space bar 6 times) - You'll get a success message ##Screenshots Here are screenshots confirming the vulnerability {F179097} {F179097} Regards, Shuaib

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Weak Cryptography for Passwords