CVE-2024-45231
MEDIUMDjango v5.1.1-v4.2.16 - Info Disclosure
Title source: llmDescription
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).
Scores
CVSS v3
5.3
EPSS
0.0024
EPSS Percentile
46.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-203
Status
published
Affected Products (3)
djangoproject/django
< 4.2.16
djangoproject/django
pypi/Django
< 5.1.1PyPI
Timeline
Published
Oct 08, 2024
Tracked Since
Feb 18, 2026