Sceawere
Vulnerability Detail
CVE-2026-104439UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki User Enumeration Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Observable Response Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T12:17:14.670Z",
"pubdate": "2026-10-02T12:17:14.670Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a user enumeration vulnerability located within the password recovery mechanism. This flaw allows unauthenticated remote attackers to verify the existence of registered user accounts by observing differential server responses when submitting arbitrary email addresses to the MotDePassePerdu recovery interface. The lack of rate-limiting controls exacerbates the risk, enabling automated harvesting of valid email addresses associated with the system. This information disclosure provides attackers with a verified target list for downstream malicious activities, including credential stuffing, targeted phishing campaigns, or sophisticated password-spraying attacks. The vulnerability resides in the application's failure to sanitize error messaging or provide uniform response latency, effectively leaking account existence to external actors.",
"technicalDetails": "The vulnerability originates in LostPasswordAction.php, which serves as the backend controller for the password recovery process. The root cause is a logic flaw in the handling of email address verification during the password reset request lifecycle. When a user submits an email address to the recovery endpoint, the application performs an internal lookup to verify if the provided email corresponds to an active account within the system database.\nThe application generates distinct responses based on the outcome of this lookup. If an email address is not found in the repository, the application returns a specific error notification indicating that the user does not exist. Conversely, if the email is found, the system may suppress the error, indicate that a reset link has been dispatched, or return a different HTTP status code or message payload. By monitoring these response variances, an attacker can programmatically distinguish between valid and invalid email addresses.\nThe attack flow follows a sequential enumeration process. An unauthenticated attacker interacts with the application via the MotDePassePerdu component. The attacker provides a list of candidate email addresses in a series of automated HTTP POST requests. Because the application fails to implement rate limiting, CAPTCHA mechanisms, or account lockout policies, an attacker can submit a high volume of requests in a short duration. The attacker parses the server's HTTP response headers and body content for each request to categorize the email as 'registered' or 'unregistered'.\nThis vulnerability is classified as an information disclosure issue, occurring in an unauthenticated context with no privilege requirements. It is exposed over the network, allowing any remote actor to interact with the web interface. The post-exploitation impact is significant, as the successful identification of valid user accounts facilitates the execution of secondary, more intrusive attacks. By confirming a mapping between public email identities and the specific YesWiki instance, the attacker effectively narrows the attack surface for subsequent credential-based attacks, significantly increasing the probability of a successful account compromise through password-spraying or automated brute-force attempts on the recovered accounts."
}