CVE-2019-25338
Last modified
CVE-2019-25338 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dokuwiki | Dokuwiki | 2018-04-22b |
References
- https://www.exploit-db.com/exploits/47731Exploit, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-25338?
How severe is CVE-2019-25338?
How do I fix CVE-2019-25338?
Are you affected by CVE-2019-25338?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
