An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
| Software | From | Fixed in |
|---|---|---|
| backdropcms / backdrop_cms | - | 1.22.0.x |