Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
{ "nvd_published_at": "2022-12-25T05:15:00Z", "cwe_ids": [ "CWE-203" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-12-30T17:19:02Z" }