Reset Password Feature in Pagekit Reveals User Account Information
CVE-2019-16669

5.3MEDIUM

Key Information:

Vendor

Pagekit

Status
Vendor
CVE Published:
21 September 2019

What is CVE-2019-16669?

The Reset Password feature in Pagekit version 1.0.17 exhibits a vulnerability that allows a malicious actor to discern valid user accounts. When an email address is submitted, the system's response differs based on whether the address corresponds to a valid user, enabling attackers to determine existing accounts. This functionality flaw can potentially be exploited to compromise user information and conduct further attacks.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.