The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Description The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
Title Frontier Airlines publicly available email address validation
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-10-23T19:31:15.979Z

Reserved: 2025-10-09T18:26:38.378Z

Link: CVE-2025-62236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-23T20:15:40.890

Modified: 2025-10-23T20:15:40.890

Link: CVE-2025-62236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.