CVE-2025-46047: Input Validation
Published Sep 2, 2025
·Updated
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.
Affected Software
4 affected componentsFixes available
Silverpeas Silverpeas>=6.4.1<=6.4.2
maven/org.silverpeas.core:silverpeas-core>=6.4.1<6.4.3
6.4.3
Silverpeas Silverpeas=6.4.1
Silverpeas Silverpeas=6.4.2
Remediation
Patch Available
Event History
Sep 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:31 PM
Data Sourced
via GitHub·03:31 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46047?
CVE-2025-46047 is classified as a user enumeration vulnerability with a significant impact, allowing attackers to identify valid usernames.
2
How do I fix CVE-2025-46047?
To fix CVE-2025-46047, upgrade your Silverpeas installation to a version that is not vulnerable, specifically versions beyond 6.4.2.
3
Which versions of Silverpeas are affected by CVE-2025-46047?
CVE-2025-46047 affects Silverpeas versions 6.4.1 and 6.4.2.
4
What can attackers do with CVE-2025-46047?
Attackers can exploit CVE-2025-46047 to determine valid usernames through the Forgot Password functionality.
5
Is there a public proof-of-concept for CVE-2025-46047?
Yes, there are public proof-of-concept examples demonstrating the exploitation of CVE-2025-46047.