User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
5.3CVSS
5.4AI Score
0.001EPSS
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing userΒ΄s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values becau...
7.5CVSS
7.5AI Score
0.001EPSS