First published: Wed Mar 15 2017(Updated: )
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/weblate | <2.10.1 | 2.10.1 |
Weblate | <=2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5537 is considered a medium severity vulnerability due to the potential for user account enumeration.
To fix CVE-2017-5537, upgrade Weblate to version 2.10.1 or later.
CVE-2017-5537 allows attackers to determine if an email address is associated with a user account, leading to account enumeration.
CVE-2017-5537 is present in Weblate versions prior to 2.10.1.
CVE-2017-5537 is classified as an information disclosure vulnerability.