Описание
Pimcore Discloses Usernames In Use
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
Пакеты
Наименование
pimcore/pimcore
composer
Затронутые версииВерсия исправления
< 6.2.2
6.2.2
Связанные уязвимости
CVSS3: 7.5
nvd
около 6 лет назад
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.