Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3x8-6898-23g3

Опубликовано: 17 окт. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

ibexa/user login enumerates user accounts

Impact

In v5, error messages could provide enough information to tell whether a user exists or not. This is resolved by ensuring the error messages are sufficiently ambigious.

Patches

See "Patched versions".

Workarounds

None.

Resources

https://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office

Пакеты

Наименование

ibexa/user

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.3

5.0.3

6.9 Medium

CVSS4

Дефекты

CWE-209

6.9 Medium

CVSS4

Дефекты

CWE-209