CVE-2022-23172
MEDIUMPriority < 22.0 - Password Reset Weakness
Title source: ruleDescription
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
Scores
CVSS v3
5.5
EPSS
0.0013
EPSS Percentile
32.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-640
Status
published
Affected Products (1)
priority-software/priority
< 22.0
Timeline
Published
Jul 06, 2022
Tracked Since
Feb 18, 2026