An issue exists in Serenity Serene (and StartSharp) prior to 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
serenity serene |
||
serenity startsharp |