Unrated severityNVD Advisory· Published Jul 6, 2022· Updated Sep 16, 2024
Priority - Priority User Enumeration
CVE-2022-23172
Description
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.gov.il/en/departments/faq/cve_advisoriesmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.