Impact
The vulnerability in Softtr Informatics Trading Limited Company's E-Commerce Pack allows an attacker to perform account footprinting through observable discrepancies in application responses. By interacting with the web interface or API, a malicious actor can identify the existence or absence of user accounts, thereby enabling targeted credential guessing or other enumeration attacks. The weakness is classified as CWE‑203 and primarily threatens the confidentiality of user identities.
Affected Systems
Softtr Informatics Trading Limited Company's E-Commerce Pack, all releases through 2026‑10‑02, as stated by the vendor. No further sub‑version detail is available, so any deployment of this product should be considered affected pending a vendor fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, suggesting it has not yet been widely imported or used in malicious attacks. The likely attack vector is remote via the public web interface or API of the e‑commerce application. An attacker would craft requests that elicit different responses based on whether an account exists, then observe these discrepancies to enumerate valid usernames or email addresses.
OpenCVE Enrichment