PT-2005-3931 · Six Apart · Movable Type
Published
2005-09-28
·
Updated
2008-09-05
·
CVE-2005-3101
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Movable Type versions prior to 3.2
Description
The password reset feature generates different error messages depending on whether a user exists or not, allowing remote attackers to determine valid usernames.
Recommendations
For versions prior to 3.2, update to version 3.2 or later to resolve the issue. As a temporary workaround, consider modifying the password reset feature to return generic error messages, preventing attackers from determining valid usernames.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Movable Type