Lucene search

K
cvelistMitreCVELIST:CVE-2023-31286
HistoryApr 27, 2023 - 12:00 a.m.

CVE-2023-31286

2023-04-2700:00:00
mitre
www.cve.org
1
cve-2023-31286
serenity serene
startsharp
password reset
user existence leak

EPSS

0.001

Percentile

37.4%

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.

EPSS

0.001

Percentile

37.4%

Related for CVELIST:CVE-2023-31286