PT-2025-49144 · Unknown · Kalmia Cms
Published
2025-12-04
·
Updated
2025-12-05
·
CVE-2025-65899
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kalmia CMS version 0.2.0
Description
The application exhibits a user enumeration issue in its authentication process. Different error messages are returned depending on whether a user exists or not, or if the password is incorrect. Specifically, the application returns distinct responses for invalid users (
user not found) versus valid users with incorrect credentials (invalid password). This allows attackers to identify valid usernames without authentication.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kalmia Cms