CVE-2023-53943

GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glpi-project:glpi:9.5.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-18 20:15

Updated : 2025-12-31 17:34


NVD link : CVE-2023-53943

Mitre link : CVE-2023-53943

CVE.ORG link : CVE-2023-53943


JSON object : View

Products Affected

glpi-project

  • glpi
CWE
CWE-203

Observable Discrepancy