An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-08-01T19:24:37

Updated: 2022-08-01T19:24:36

Reserved: 2022-06-26T00:00:00


Link: CVE-2022-34530

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-01T20:15:08.810

Modified: 2022-08-08T15:25:22.433


Link: CVE-2022-34530

JSON object: View

cve-icon Redhat Information

No data.

CWE