CVE 5.3 MEDIUM

Saleor has user enumeration vulnerability due to different error messages_CVE-2025-58442

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

Saleor is an e-commerce platform. Starting in version 3.21.0 and prior to version 3.21.16, requesting certain fields in the response of `accountRegister` may result in errors that could unintentionally reveal whether a user with the provided email already exists in Saleor. Version 3.21.16 fixes the issue. As a workaround, rate-limit the mutation to reduce the impact.

Basic Information

ID CVE-2025-58442
Source GitHub_M
Published Sep 9, 2025 at 19:46

Affected Product

Vendor saleor
Product saleor
Version >= 3.21.0, < 3.21.16
Affected Versions saleor saleor >= 3.21.0, < 3.21.16

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.