Medium severity5.5NVD Advisory· Published Jul 6, 2022· Updated Jun 17, 2026
CVE-2022-23172
CVE-2022-23172
Description
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
Affected products
1Patches
Vulnerability mechanics
References
1- www.gov.il/en/departments/faq/cve_advisoriesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.