CVE-2023-31286
27.04.2023, 03:15
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.Enginsight
Vendor | Product | Version |
---|---|---|
serenity | serene | 𝑥 < 6.7.0 |
serenity | startsharp | 𝑥 < 6.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References