Information Exposure Affecting weblate package, versions [,2.10.1)
Threat Intelligence
EPSS
0.38% (74th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-WEBLATE-40455
- published 9 Jan 2017
- disclosed 9 Jan 2017
- credit Jelle van der Waa
Introduced: 9 Jan 2017
CVE-2017-5537 Open this link in a new tabOverview
weblate
is a web-based translation tool with tight version control integration
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
References
CVSS Scores
version 3.1