PT-2025-45155 · Quipux · Quipux

Published

2025-11-05

·

Updated

2025-11-05

·

CVE-2025-55342

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quipux versions 4.0.1 through e1774ac
Description The software allows for the enumeration of usernames and access to the Ecuadorean identification number for all registered users. This is achieved by manipulating the txt login parameter within the ''Administracion/usuarios/cambiar password olvido validar.php'' endpoint.
Recommendations Update to a version later than e1774ac.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-55342

Affected Products

Quipux