Description
PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.
Remediation
References
Related Vulnerabilities
WordPress 3.7.x Prototype Pollution (3.7 - 3.7.37)
XWikiplatform CVE-2025-48063 Vulnerability (CVE-2025-48063)
WordPress Plugin Social Sharing-Kiwi Security Bypass (2.0.10)
Moodle Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-43560)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Request Forgery (10.4.1.1)