PT-2026-1141 · Unknown · Anything-Llm
Denizparlak
·
Published
2026-01-03
·
Updated
2026-02-23
·
Denizparlak
·
Published
2026-01-03
·
Updated
2026-02-23
·
5.3
Medium
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery functionality exposed different error messages based on the existence of a username, allowing for username enumeration. The /password-recovery API endpoint was vulnerable to this issue. This allowed an attacker to determine valid usernames by observing the response to requests with different username values.e287fab56089cf8fcea9ba579a3ecdeca0daa313.Exploit
Fix
Side Channel Attack