Vulnerabilities > CVE-2023-38871 - Information Exposure Through Discrepancy vulnerability in Economizzer 0.9/April2023

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
economizzer
CWE-203

Summary

The commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer has a user enumeration vulnerability in the login and forgot password functionalities. The app reacts differently when a user or email address is valid, and when it's not. This may allow an attacker to determine whether a user or email address is valid, or brute force valid usernames and email addresses.

Vulnerable Configurations

Part Description Count
Application
Economizzer
2

Common Weakness Enumeration (CWE)