CVE-2022-34530

MEDIUM

Backdrop CMS < 1.22.0 - Username Enumeration via Password Reset Request

Title source: llm
STIX 2.1

Description

An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0059
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-640
Status published
Products (1)
backdropcms/backdrop_cms < 1.22.0
Published Aug 01, 2022
Tracked Since Feb 18, 2026