{"api_version":"1","generated_at":"2026-05-10T16:56:57+00:00","cve":"CVE-2017-5537","urls":{"html":"https://cve.report/CVE-2017-5537","api":"https://cve.report/api/cve/CVE-2017-5537.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5537","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5537"},"summary":{"title":"CVE-2017-5537","description":"The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-03-15 15:59:00","updated_at":"2017-03-21 18:56:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2017/01/20/1","name":"[oss-security] 20170119 Re: CVE request Weblate: information disclosure in password reset form","refsource":"MLIST","tags":["Mailing List","Patch"],"title":"oss-security - Re: CVE request Weblate: information disclosure in password reset form","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/95676","name":"95676","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Weblate CVE-2017-5537 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rst","name":"https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rst","refsource":"CONFIRM","tags":["Patch","Release Notes"],"title":"weblate/changes.rst at weblate-2.10.1 · WeblateOrg/weblate · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079","name":"https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079","refsource":"CONFIRM","tags":["Patch"],"title":"Do not show validation error on password reset · WeblateOrg/weblate@abe0d2a · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/WeblateOrg/weblate/issues/1317","name":"https://github.com/WeblateOrg/weblate/issues/1317","refsource":"CONFIRM","tags":["Issue Tracking","Patch"],"title":"The existence of a weblate account is guessable (CVE-2017-5537) · Issue #1317 · WeblateOrg/weblate · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2017/01/18/11","name":"[oss-security] 20170118 CVE request Weblate: information disclosure in password reset form","refsource":"MLIST","tags":["Mailing List","Patch"],"title":"oss-security - CVE request Weblate: information disclosure in password reset form","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5537","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5537","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5537","vulnerable":"1","versionEndIncluding":"2.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weblate","cpe5":"weblate","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5537","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079","refsource":"CONFIRM","url":"https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079"},{"name":"[oss-security] 20170118 CVE request Weblate: information disclosure in password reset form","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2017/01/18/11"},{"name":"https://github.com/WeblateOrg/weblate/issues/1317","refsource":"CONFIRM","url":"https://github.com/WeblateOrg/weblate/issues/1317"},{"name":"[oss-security] 20170119 Re: CVE request Weblate: information disclosure in password reset form","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2017/01/20/1"},{"name":"95676","refsource":"BID","url":"http://www.securityfocus.com/bid/95676"},{"name":"https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rst","refsource":"CONFIRM","url":"https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rst"}]}},"nvd":{"publishedDate":"2017-03-15 15:59:00","lastModifiedDate":"2017-03-21 18:56:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*","versionEndIncluding":"2.10","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5537","Ordinal":"102078","Title":"CVE-2017-5537","CVE":"CVE-2017-5537","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5537","Ordinal":"1","NoteData":"The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5537","Ordinal":"2","NoteData":"2017-03-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5537","Ordinal":"3","NoteData":"2017-03-15","Type":"Other","Title":"Modified"}]}}}