Page 1 of 1

[SOLVED] Users can choose any password like "123"

Posted: Sat Jun 30, 2018 8:17 pm
by pozzo-balbi
Hi, I just posted problem #652 under bugs.vestacp.com.

Main problem I see is that the user can change his password and choose anything, eg. 123 and then eg. login via sftp or to the control panel at port 8083 with that password. If anyone has suggestions how to fix rhel 7, that would be greatly appreciated.

Thanks

Re: Users can choose any password like "123"

Posted: Sun Jul 01, 2018 6:42 am
by joem
pozzo-balbi wrote:
Sat Jun 30, 2018 8:17 pm
Hi, I just posted problem #652 under bugs.vestacp.com.

Main problem I see is that the user can change his password and choose anything, eg. 123 and then eg. login via sftp or to the control panel at port 8083 with that password. If anyone has suggestions how to fix rhel 7, that would be greatly appreciated.

Thanks
https://github.com/serghey-rodin/vesta/pull/1638/files

Re: Users can choose any password like "123"

Posted: Sun Jul 01, 2018 2:09 pm
by pozzo-balbi
Great, and thanks for the fast update. I tested it and it is working. So I hope it will be included in further updates.