CVE-2019-16394

MEDIUM5.3EPSS 56.7%
發布日:2019/9/17修改日:2026/5/29
也稱為:DEBIAN-CVE-2019-16394

描述

SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

參考連結(1)