{"id":"CVE-2019-16669","aliases":["GHSA-jh2j-7248-9p3c"],"url":"https://o3.security/vulnerability/CVE-2019-16669","summary":"Pagekit User enumeration","details":"The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.","published":"2019-09-21T19:15:10.187Z","modified":"2026-07-08T15:55:52.772840Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"pagekit/pagekit","fixedVersion":null}],"fix":null,"references":[{"type":"REPORT","url":"https://github.com/pagekit/pagekit/issues/935"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T15:55:52.772840Z"}}