ZeroHour

CVE-2017-5537

CVSS 3.0
5.3 medium
EPSS
2%p82
Published
()
Modified
Description

The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.

Vendors
weblate
Products
weblate
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.