CVE-2019-25338: Dokuwiki 2018-04-22b - Username Enumeration
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25338?
CVE-2019-25338 is classified as a medium severity vulnerability due to its potential to expose valid usernames.
How do I fix CVE-2019-25338?
To mitigate CVE-2019-25338, update to a patched version of DokuWiki that addresses the username enumeration issue.
Can CVE-2019-25338 be exploited remotely?
Yes, CVE-2019-25338 can be exploited remotely by attackers sending HTTP requests to the password reset endpoint.
What are the potential impacts of CVE-2019-25338?
The primary impact of CVE-2019-25338 is the exposure of valid usernames, which can lead to increased risk of targeted attacks.
Which versions of DokuWiki are affected by CVE-2019-25338?
CVE-2019-25338 affects DokuWiki version 2018-04-22b and prior releases.