Описание
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
Ссылки
- Mailing ListPatch
- Mailing ListPatch
- Third Party AdvisoryVDB Entry
- PatchRelease Notes
- Patch
- Issue TrackingPatch
- Mailing ListPatch
- Mailing ListPatch
- Third Party AdvisoryVDB Entry
- PatchRelease Notes
- Patch
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1Версия до 2.10 (включая)
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00543
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.3
debian
почти 9 лет назад
The password reset form in Weblate before 2.10.1 provides different er ...
CVSS3: 5.3
github
больше 3 лет назад
Weblate user account enumeration via reset password form
EPSS
Процентиль: 67%
0.00543
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200