GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 Jan 2026 02:45:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:glpi-project:glpi:9.5.7:*:*:*:*:*:*:*

Fri, 19 Dec 2025 18:30:00 +0900

Type Values Removed Values Added
First Time appeared Glpi-project
Glpi-project glpi
Vendors & Products Glpi-project
Glpi-project glpi

Fri, 19 Dec 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 05:00:00 +0900

Type Values Removed Values Added
Description GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.
Title GLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint
Weaknesses CWE-203
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-18T21:19:27.512Z

Reserved: 2025-12-16T19:22:09.998Z

Link: CVE-2023-53943

cve-icon Vulnrichment

Updated: 2025-12-18T21:01:38.136Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-18T20:15:52.940

Modified: 2025-12-31T17:34:30.613

Link: CVE-2023-53943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-19T18:15:38Z

Weaknesses