In versions of notrinos/notrinoserp prior to 0.7 new account passwords were missing a password strength check. References https://nvd.nist.gov/vuln/detail/CVE-2022-2927 https://github.com/notrinos/notrinoserp/commit/e61e76b44c6a2b28a4a648a06ef34f65c376ec1e https://huntr.dev/bounties/7fa956dd-f541-4dcd-987d-ba15caa6a886 https://github.com/advisories/GHSA-qhm8-69qh-g76j