CVE-2017-5537 – weblate
Package
Manager: pip
Name: weblate
Vulnerable Version: >=0 <2.10.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00543 pctl0.66749
Details
Weblate user account enumeration via reset password form The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
Metadata
Created: 2022-05-17T02:54:32Z
Modified: 2024-11-19T16:05:15Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j24g-gm76-j829/GHSA-j24g-gm76-j829.json
CWE IDs: ["CWE-200", "CWE-209"]
Alternative ID: GHSA-j24g-gm76-j829
Finding: F310
Auto approve: 1