The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
History

Mon, 27 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Frontier Airlines
Frontier Airlines flyfrontier
Vendors & Products Frontier Airlines
Frontier Airlines flyfrontier

Thu, 23 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Description The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
Title Frontier Airlines publicly available email address validation
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2025-10-23T19:31:15.979Z

Updated: 2025-10-27T13:45:00.638Z

Reserved: 2025-10-09T18:26:38.378Z

Link: CVE-2025-62236

cve-icon Vulnrichment

Updated: 2025-10-27T13:44:53.388Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-23T20:15:40.890

Modified: 2025-10-27T13:20:15.637

Link: CVE-2025-62236

cve-icon Redhat

No data.