•  
      request #43674 User enumeration via the lost password form
    Infos
    #43674
    Thomas Gerbet (tgerbet)
    2025-07-22 14:46
    2025-06-20 11:40
    45364
    Details
    User enumeration via the lost password form

    Impact

    The forgot password form allows for user enumeration.
    CVSSv3.1 score: 5.3 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

    References

    CWE 204
    Forgot Password - OWASP Cheat Sheet
    CVE-2025-52899

    Acknowledgements

    The issue has been identified by AlgoSecure penetration testing team during an audit sponsored by Enalean.

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Antoine Sauzeau (antoinesauzeau)
    Closed
    2025-06-25
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-06-27 09:45

    CVE-2025-52899 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-06-20 11:42
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes