CVE-2017-5537
published 2017-03-15CVE-2017-5537: The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which…
PriorityP424medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | <= 2.10 | — |
| weblate | weblate | >= 0 < 2.10.1 | 2.10.1 |
| weblate | weblate | >= 0 < abe0d2a29a1d8e896bfe829c8461bf8b391f1079 | abe0d2a29a1d8e896bfe829c8461bf8b391f1079 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Weblate user account enumeration via reset password form
osv·2022-05-17
CVE-2017-5537 [MEDIUM] Weblate user account enumeration via reset password form
Weblate user account enumeration via reset password form
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
GHSA
Weblate user account enumeration via reset password form
ghsa·2022-05-17
CVE-2017-5537 [MEDIUM] CWE-200 Weblate user account enumeration via reset password form
Weblate user account enumeration via reset password form
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
OSV
CVE-2017-5537: The password reset form in Weblate before 2
osv·2017-03-15
CVE-2017-5537 CVE-2017-5537: The password reset form in Weblate before 2
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2017/01/18/11http://www.openwall.com/lists/oss-security/2017/01/20/1http://www.securityfocus.com/bid/95676https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rsthttps://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079https://github.com/WeblateOrg/weblate/issues/1317http://www.openwall.com/lists/oss-security/2017/01/18/11http://www.openwall.com/lists/oss-security/2017/01/20/1http://www.securityfocus.com/bid/95676https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rsthttps://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079https://github.com/WeblateOrg/weblate/issues/1317
2017-03-15
Published