Weak Password Policies in Mangati NovoSGA Software
CVE-2025-11322

6.3MEDIUM

Key Information:

Vendor

Mangati

Status
Vendor
CVE Published:
6 October 2025

What is CVE-2025-11322?

A vulnerability exists in Mangati NovoSGA, specifically in the User Creation Page, which allows for the manipulation of password creation parameters. This flaw can lead to the implementation of weak password requirements, which can be exploited remotely. Although the complexity of the attack is considered high, the potential for exploitation remains a concern. The vendor was notified about this issue but has not responded to the disclosure. Users are advised to carefully manage their password policies to avoid potential security risks.

Affected Version(s)

NovoSGA 2.2.0

NovoSGA 2.2.1

NovoSGA 2.2.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

marceloQz (VulDB User)
marceloQz (VulDB User)
.
CVE-2025-11322 : Weak Password Policies in Mangati NovoSGA Software