Q's blog

Home About me

Q | CVE-2024-51051 Weak Password Policy in AVSCMS 8.2.0

Description

This is a public record, and or proof of concept regarding CVE-2024-51051, a vulnerability affecting AVSCMS version 8.2.0 which includes:

  1. Weak default credential
  2. Lack of passsword policy / management

Nothing much to be said about the vulnerability, by default AVSCMS have admin:admin credential. The application also didn't have any password's strength policy for their user, nor an interface for setting up password strength under their site-admin panel.

Impact

This vulnerability allows attacker to have an easier time guessing the user's or admin's password (either via bruteforce or dictionary attack).

Weak default admin:admin

Weak default admin credential.

Login and register possible using weak password

Here I logged in using normal user with weak password.

Lack of password strength management

Lack of password strength management

  1. Related CWE-1391
  2. Related CWE-1392
  3. Related CWE-521