CVE-2026-64822

MEDIUM

djangoSIGE 1.10 User Enumeration via ForgotPasswordView

Title source: cna
STIX 2.1

Description

djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosige/apps/login/views.py that allows unauthenticated attackers to identify valid accounts by observing distinct error messages returned by the password reset endpoint. Attackers can submit arbitrary usernames or email addresses to the POST login/esqueceu/ endpoint and distinguish between existing and non-existing accounts based on observable discrepancies in the application's responses.

References (3)

Core 3

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (2)
thiagopena/djangoSIGE < 1.10
thiagopena/djangoSIGE < a6fe7e8e3a7d52ba0a25305df4e5e7e0cd5f5792
Published Jul 21, 2026
Tracked Since Jul 22, 2026