User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.
This was originally disclosed in https://www.silverstripe.org/download/security-releases/ss-2017-005/ for CMS 3 but was not patched in CMS 4+
{ "nvd_published_at": null, "cwe_ids": [ "CWE-204" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-10T20:12:55Z" }