CVE-2019-25338
Awaiting Analysis
Awaiting Analysis - Queue
Username Enumeration in DokuWiki Password Reset Function Allows Account Disclosure
Publication date: 2026-02-12
Last updated on: 2026-03-02
Assigner: VulnCheck
Description
Description
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dokuwiki | dokuwiki | 2018-04-22b |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |