Description
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting.

This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Account Footprinting (User Enumeration)
Action: Assess Impact
AI Analysis

Impact

The vulnerability in Softtr Informatics Trading Limited Company's E-Commerce Pack allows an attacker to perform account footprinting through observable discrepancies in application responses. By interacting with the web interface or API, a malicious actor can identify the existence or absence of user accounts, thereby enabling targeted credential guessing or other enumeration attacks. The weakness is classified as CWE‑203 and primarily threatens the confidentiality of user identities.

Affected Systems

Softtr Informatics Trading Limited Company's E-Commerce Pack, all releases through 2026‑10‑02, as stated by the vendor. No further sub‑version detail is available, so any deployment of this product should be considered affected pending a vendor fix.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, suggesting it has not yet been widely imported or used in malicious attacks. The likely attack vector is remote via the public web interface or API of the e‑commerce application. An attacker would craft requests that elicit different responses based on whether an account exists, then observe these discrepancies to enumerate valid usernames or email addresses.

Generated by OpenCVE AI on October 2, 2026 at 13:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version released after 2026‑10‑02 when it becomes available.
  • Configure the application to return a nonspecific, generic response for all authentication or account‑lookup requests, thereby removing client‑side clues that reveal account existence.
  • Enable account lockout policies or rate limiting on authentication attempts to deter automated enumeration efforts.
  • Monitor application logs and traffic for repeated or abnormal authentication patterns that may indicate enumeration attacks.

Generated by OpenCVE AI on October 2, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title User Enumeration in Softtr's E-Commerce Pack
Weaknesses CWE-203
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-02T12:42:19.549Z

Reserved: 2026-06-09T13:13:01.603Z

Link: CVE-2026-11795

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T13:17:45.160

Modified: 2026-10-02T13:17:45.160

Link: CVE-2026-11795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:06Z

Weaknesses