← Back

CVE-2023-31286

nvd nist
Published: Apr 27, 2023Modified: Jan 31, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.

Affected (2)

2 products
Serene
Startsharp
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.7.0
Before 6.7.0

Timeline

No history available yet.