CVE-2017-5537

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
15/03/2017
Last modified:
20/04/2025

Description

The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* 2.10 (including)