Sceawere

Vulnerability Detail

CVE-2026-104439UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki User Enumeration Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Observable Response Discrepancy
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:14.670Z",
  "pubdate": "2026-10-02T12:17:14.670Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a user enumeration vulnerability located within the password recovery mechanism. This flaw allows unauthenticated remote attackers to verify the existence of registered user accounts by observing differential server responses when submitting arbitrary email addresses to the MotDePassePerdu recovery interface. The lack of rate-limiting controls exacerbates the risk, enabling automated harvesting of valid email addresses associated with the system. This information disclosure provides attackers with a verified target list for downstream malicious activities, including credential stuffing, targeted phishing campaigns, or sophisticated password-spraying attacks. The vulnerability resides in the application's failure to sanitize error messaging or provide uniform response latency, effectively leaking account existence to external actors.",
  "technicalDetails": "The vulnerability originates in LostPasswordAction.php, which serves as the backend controller for the password recovery process. The root cause is a logic flaw in the handling of email address verification during the password reset request lifecycle. When a user submits an email address to the recovery endpoint, the application performs an internal lookup to verify if the provided email corresponds to an active account within the system database.\nThe application generates distinct responses based on the outcome of this lookup. If an email address is not found in the repository, the application returns a specific error notification indicating that the user does not exist. Conversely, if the email is found, the system may suppress the error, indicate that a reset link has been dispatched, or return a different HTTP status code or message payload. By monitoring these response variances, an attacker can programmatically distinguish between valid and invalid email addresses.\nThe attack flow follows a sequential enumeration process. An unauthenticated attacker interacts with the application via the MotDePassePerdu component. The attacker provides a list of candidate email addresses in a series of automated HTTP POST requests. Because the application fails to implement rate limiting, CAPTCHA mechanisms, or account lockout policies, an attacker can submit a high volume of requests in a short duration. The attacker parses the server's HTTP response headers and body content for each request to categorize the email as 'registered' or 'unregistered'.\nThis vulnerability is classified as an information disclosure issue, occurring in an unauthenticated context with no privilege requirements. It is exposed over the network, allowing any remote actor to interact with the web interface. The post-exploitation impact is significant, as the successful identification of valid user accounts facilitates the execution of secondary, more intrusive attacks. By confirming a mapping between public email identities and the specific YesWiki instance, the attacker effectively narrows the attack surface for subsequent credential-based attacks, significantly increasing the probability of a successful account compromise through password-spraying or automated brute-force attempts on the recovered accounts."
}
CVE-2026-104439: YesWiki User Enumeration Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere