An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-08-01T19:24:37
Updated: 2024-08-03T09:15:15.261Z
Reserved: 2022-06-26T00:00:00
Link: CVE-2022-34530
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-08-01T20:15:08.810
Modified: 2022-08-08T15:25:22.433
Link: CVE-2022-34530
Redhat
No data.