
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw has been found in Mangati NovoSGA up to version 2.2.12, identified as CVE-2025-11322. The vulnerability affects the User Creation Page component, specifically in the file /novosga.users/new, where weak password requirements can be exploited through manipulation of the Senha/Confirmação da senha argument (NVD).
The vulnerability has been assessed with multiple CVSS scores: CVSS v4.0 score of 6.3 (Medium) with vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P, and CVSS v3.1 score of 3.7 (Low) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is classified under CWE-521 (Weak Password Requirements) (NVD).
The vulnerability allows remote exploitation, though attacks are considered highly complex. The primary impact is related to weak password requirements, which could potentially compromise account security (NVD).
The vendor was contacted early about this disclosure but did not respond in any way. No official patches or mitigations have been published (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."