The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.
{
"github_reviewed_at": "2024-04-24T20:18:24Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-203"
],
"nvd_published_at": "2019-09-21T19:15:00Z",
"github_reviewed": true
}