CVE-2023-53943: GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint
GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53943?
CVE-2023-53943 has been classified as a high severity vulnerability due to its ability to facilitate username enumeration.
How do I fix CVE-2023-53943?
To fix CVE-2023-53943, update GLPI to the latest version that addresses the username enumeration in the lost password recovery mechanism.
Who is affected by CVE-2023-53943?
Users of GLPI version 9.5.7 and below are affected by CVE-2023-53943.
What does CVE-2023-53943 allow attackers to do?
CVE-2023-53943 allows attackers to validate email addresses by submitting requests to the password reset endpoint.
Is CVE-2023-53943 a serious risk for my application?
Yes, CVE-2023-53943 is a serious risk as it can lead to unauthorized disclosure of valid usernames.