GHSA-xgr2-5837-hf48

Suggest an improvement
Source
https://github.com/advisories/GHSA-xgr2-5837-hf48
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-xgr2-5837-hf48/GHSA-xgr2-5837-hf48.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xgr2-5837-hf48
Aliases
  • CVE-2025-11322
Published
2025-10-06T06:32:58Z
Modified
2025-10-07T13:57:23Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
Details

A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can lead to weak password requirements. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is regarded as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-521"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-07T13:42:48Z",
    "nvd_published_at": "2025-10-06T06:15:35Z",
    "severity": "LOW"
}
References

Affected packages

Packagist / novosga/novosga

Package

Name
novosga/novosga
Purl
pkg:composer/novosga/novosga

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.2.12

Affected versions

v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.4.0
v1.4.1
v1.5.0
v1.5.1
v1.5.2
v2.*
v2.0.0-BETA1
v2.0.0-BETA2
v2.0.0-BETA3
v2.0.0-BETA4
v2.0.0-BETA5
v2.0.0-BETA6
v2.0.0-RC2
v2.0.0-RC3
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.0.10
v2.0.11
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9
v2.2.0-beta.1
v2.2.0-beta.2
v2.2.0
v2.2.1
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.2.10
v2.2.11
v2.2.12
2.*
2.0.0-RC1
2.2.2
2.2.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-xgr2-5837-hf48/GHSA-xgr2-5837-hf48.json"