Sceawere
Vulnerability Detail
CVE-2026-11795UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
E-Commerce Pack Account Footprinting
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 10h ago
- Vendor
- Softtr Informatics Trading Limited Company
- Product
- E-Commerce Pack
- Attack Type
- CWE-203 Observable discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T13:17:45.160Z",
"pubdate": "2026-10-02T13:17:45.160Z",
"executiveSummary": "The Softtr Informatics Trading Limited Company E-Commerce Pack is susceptible to an observable discrepancy vulnerability that facilitates account footprinting.\nThis vulnerability allows unauthenticated or low-privileged attackers to differentiate between valid and invalid user identifiers by observing subtle variations in system responses.\nThe primary impact of this flaw is the leakage of sensitive user existence information, which significantly lowers the barrier for subsequent targeted attacks, such as credential stuffing, brute-force password spraying, or social engineering campaigns.\nThe vulnerability affects all versions of the E-Commerce Pack through 2026-10-02.\nThe vendor has not responded to disclosure attempts, leaving the implementation vulnerable to active exploitation by threat actors looking to map the user base of affected e-commerce installations.\nOrganizations deploying this software must assume that attacker-driven enumeration of registered accounts is possible and implement proactive defensive measures to mitigate the risk of account takeovers.",
"technicalDetails": "The vulnerability originates from an observable discrepancy during the authentication or account management flow, where the application exhibits distinct behavioral patterns based on whether a submitted user identifier exists within the underlying database.\nThis discrepancy typically manifests as variations in HTTP response metadata, such as differences in response status codes (e.g., 200 OK vs. 401 Unauthorized), variations in timing profiles (side-channel analysis), or differences in verbose error messages returned to the client.\nAn attacker can systematically supply a list of common email addresses or usernames to the application's login, password recovery, or account registration endpoints. By monitoring the server's response time or the specific content of the returned payload, the attacker can verify the existence of these accounts with a high degree of confidence.\nFor instance, if an endpoint returns a specific error message like 'User not found' versus a generic 'Invalid credentials' message, or if a password recovery endpoint indicates that an email has been sent for a valid account while timing out or rejecting an invalid one, the binary state of 'exists' or 'does not exist' is exposed.\nThis behavior constitutes an information disclosure vulnerability that enables account footprinting. By building a verified list of active user accounts, an attacker establishes a prerequisite for automated credential stuffing attacks, where known credentials leaked from other breaches are tested against the verified user base of the E-Commerce Pack.\nBecause this information is available via standard network interactions without requiring prior authentication or elevated privileges, the attack vector is highly accessible. The flaw persists across all software versions up to and including the 2026-10-02 build. The lack of vendor-supplied patches means that the vulnerability remains inherently present in the current production codebase, necessitating manual hardening at the application logic or infrastructure layer to normalize response behaviors and obfuscate existence verification attempts."
}