5
CVSSv2

CVE-2017-5537

Published: 15/03/2017 Updated: 21/03/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The password reset form in Weblate prior to 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote malicious users to enumerate user accounts via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

weblate weblate