Loading HuntDB...

Setting a password with a single character

Low
W
Weblate
Submitted None
Reported by footstep

Vulnerability Details

Technical details and impact analysis

Weak Cryptography for Passwords
Hi!, Following my previous report, #223618, I could see that you made a change to the site which https://demo.weblate.org/accounts/password/ says >Your password can't be too similar to your other personal information. >Your password must contain at least 6 characters. >Your password can't be a commonly used password. >Your password can't be entirely numeric. >**Your password can't consist of single character or whitespace only.** I found that it is possible to create a password with a single character ###Reproduction Steps - Create a new account - Load the link sent to your mail - Now, set password to six spaces(tapping the space bar 6 times) and a letter included - You'll get a success message. ##Screenshot {F179412} {F179413} Regards, Shuaib

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Weak Cryptography for Passwords