CVE-2023-38871

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/09/2023
Last modified:
03/10/2023

Description

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to determine whether a user or email address is valid, or brute force valid usernames and email addresses.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:economizzer:economizzer:0.9:beta1:*:*:*:wordpress:*:*
cpe:2.3:a:economizzer:economizzer:april_2023:*:*:*:*:wordpress:*:*