CVE-2022-23172

MEDIUM

Priority < 22.0 - Password Reset Weakness

Title source: rule

Description

An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 32.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-640
Status published

Affected Products (1)

priority-software/priority < 22.0

Timeline

Published Jul 06, 2022
Tracked Since Feb 18, 2026