« Notes

Email enumeration attack.

It’s when an attacker can check if an email exists in a system (for example, on password reset forms, with “There’s no such email in the system” error messages).