CVE-2019-25338

Source
https://cve.org/CVERecord?id=CVE-2019-25338
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25338.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-25338
Aliases
Downstream
Published
2026-02-12T23:16:07.670Z
Modified
2026-07-08T19:50:43.429293Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

References

Affected packages

Git / github.com/dokuwiki/dokuwiki

Affected ranges

Type
GIT
Repo
https://github.com/dokuwiki/dokuwiki
Events
Database specific
{
    "cpe": "cpe:2.3:a:dokuwiki:dokuwiki:2018-04-22b:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "2018-04-22b"
        },
        {
            "last_affected": "2018-04-22b"
        }
    ]
}

Affected versions

Other
2018-04-22b
release-2018-04-22c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25338.json"