PT-2025-52322 · Glpi · Glpi

Rafael B

·

Published

2025-12-18

·

Updated

2025-12-31

·

CVE-2023-53943

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GLPI version 9.5.7
Description The software contains a flaw in the password recovery process that allows for username enumeration. An attacker can validate email addresses by submitting requests to the password reset functionality and observing the responses to determine valid user accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2023-53943

Affected Products

Glpi