Vulnerabilities > CVE-2023-3221 - Information Exposure Through Discrepancy vulnerability in Password Recovery Project Password Recovery 1.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |