Vulnerability Description
The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addresses, possibly aiding in further attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flyfrontier | Frontier Airlines | - |
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-62236Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2025-62236?
CVE-2025-62236 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with an account. An unauthenticated, remote attacker could determine valid email addr...
How severe is CVE-2025-62236?
CVE-2025-62236 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62236?
Check the references section above for vendor advisories and patch information. Affected products include: Flyfrontier Frontier Airlines.