Описание
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
Ссылки
- Third Party Advisory
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:flyfrontier:frontier_airlines:-:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00047
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-204
Связанные уязвимости
CVSS3: 5.3
github
4 месяца назад
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
EPSS
Процентиль: 15%
0.00047
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-204