Default account creation on all installation methods in alextselegidis/easyappointments
Reported on
Feb 6th 2023
Description
The credentials of the administrator user (console installation) are set by default. Additionally in both the console installation and the gui installation a janedoe account is created with default credentials.
Impact
An attacker could exploit this vulnerability by remotely Logging in into an affected system by using the Default Credentials.
Hello!
Thanks for submitting this.
I've updated the seeders to provide custom passwords wherever there is no UI input for them.