CVE-2025-60954 - CERT CVE
ID CVE-2025-60954
Sažetak Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.
Reference
CVSS
Base: 8.3
Impact: 5.5
Exploitability:2.8
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Zadnje važnije ažuriranje 24-10-2025 - 21:16
Objavljeno 24-10-2025 - 21:16