Impact
DernekPlus Website Template contains an observable response discrepancy that allows an attacker to determine whether a specific account exists. This vulnerability enables account footprinting, exposing user identities and potentially aiding further attacks. The weakness is reflected by CWE-204, indicating an improper validation that leads to information leakage.
Affected Systems
The affected product is DernekPlus Website Template. All releases through version 10092026 are impacted. No specific subcomponents or configurations are mentioned beyond the template itself.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access via the public web interface, where an attacker can send crafted requests to probe account existence and observe the response differences. Because the vendor has not released a fix, the risk persists until a new version or patch is applied.
OpenCVE Enrichment