Weak Password Policies in Mangati NovoSGA Software
CVE-2025-11322
6.3MEDIUM
What is CVE-2025-11322?
A vulnerability exists in Mangati NovoSGA, specifically in the User Creation Page, which allows for the manipulation of password creation parameters. This flaw can lead to the implementation of weak password requirements, which can be exploited remotely. Although the complexity of the attack is considered high, the potential for exploitation remains a concern. The vendor was notified about this issue but has not responded to the disclosure. Users are advised to carefully manage their password policies to avoid potential security risks.
Affected Version(s)
NovoSGA 2.2.0
NovoSGA 2.2.1
NovoSGA 2.2.2
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
marceloQz (VulDB User)
marceloQz (VulDB User)