Atjiu Pybbs Weak Password Policy Vulnerability in UserAdminController

Vulnerability

A critical vulnerability exists in Atjiu Pybbs versions up to 6.0.0, specifically in the UserAdminController.java file. The issue arises in the 'update' function, where password requirements are insufficiently enforced. This flaw allows users to create accounts with weak passwords, potentially consisting of a single digit. Such lax requirements can lead to account compromises through password guessing or brute-force attacks. The vulnerability can be exploited remotely, and while the exploitation is considered difficult, a public exploit is available.

Impact

Exploitation of this vulnerability allows for the creation of accounts with weak passwords, increasing the risk of account compromise through guessing or brute-force methods.

Reproduction

To reproduce this vulnerability, register a new account on an Atjiu Pybbs instance running a version prior to 6.0.0. During the registration process, enter a password that does not meet typical security standards, such as a single digit. The account will be created successfully, demonstrating the lack of a robust password policy.

Remediation

Users are advised to update to the latest version of Atjiu Pybbs, where this vulnerability has been addressed.

Added: Aug 5, 2025, 7:19 AM
Updated: Aug 5, 2025, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.0
remediation
7.7
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.