CVE-2026-11795: User Enumeration in Softtr's E-Commerce Pack
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting.
This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What can an unauthenticated attacker learn from this issue?
The issue allows account footprinting through observable discrepancies, enabling an attacker to enumerate or infer the existence of accounts. The reported impact is limited to confidentiality; no integrity or availability impact is specified.
Does exploitation require credentials or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What product versions are affected?
The affected range is reported as E-Commerce Pack through 2026-10-02. No fixed version or vendor remediation is identified in the provided data.
Is a vendor patch or response available?
No vendor response is reported. The vendor was contacted early about the disclosure but did not respond, and the provided information does not identify a patch or mitigation.