PT-2026-73180 · Automad · Automad
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
automad versions prior to 2.0.0-beta.33
Description
A remote issue exists in the Password Reset Endpoint within the
requestPasswordResetToken() function of the automad/src/server/Controllers/API/UserController.php file. Manipulation of the name-or-email argument leads to an observable response discrepancy, which can be used to distinguish between valid and invalid users. This attack is characterized by high complexity and difficult exploitability.Recommendations
Upgrade to version 2.0.0-beta.33.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Automad