ZeroHour

CVE-2022-34530

CVSS 3.1
5.3 medium
EPSS
<1%p47
Published
()
Modified
Description

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.

Vendors
backdropcms
Products
backdrop cms
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.