Executive brief
djangoSIGE, an open-source enterprise resource planning (ERP) system, is vulnerable to user enumeration. An unauthorized attacker can use the password reset feature to determine if specific usernames or email addresses are registered in the system by observing different error messages. This information can be used to build target lists for more serious attacks like account takeovers or phishing.
Technical details
A user enumeration vulnerability exists in djangoSIGE through version 1.10 (commit a6fe7e8) within the ForgotPasswordView located in djangosige/apps/login/views.py. The application returns distinct error messages (e.g., 'Usuário/Email: {value} não foi encontrado na database') when a non-existent username or email is submitted to the password reset endpoint (POST /login/esqueceu/), compared to the success message returned for valid accounts. This observable discrepancy (CWE-203) allows a remote, unauthenticated attacker to verify the existence of accounts. A fix has been proposed in pull request #163 which implements generic response messages for both scenarios.
Affected products
- thiagopena djangoSIGE through 1.10 (commit a6fe7e8)
Timeline
- 2026-07-21: advisory: Public disclosure and CVE assignment via VulnCheck
- 2026-07-21: patched: Pull request #163 submitted with fix