Reset Password Feature in Pagekit Reveals User Account Information
CVE-2019-16669
5.3MEDIUM
What is CVE-2019-16669?
The Reset Password feature in Pagekit version 1.0.17 exhibits a vulnerability that allows a malicious actor to discern valid user accounts. When an email address is submitted, the system's response differs based on whether the address corresponds to a valid user, enabling attackers to determine existing accounts. This functionality flaw can potentially be exploited to compromise user information and conduct further attacks.
