CVE-2019-16394

MEDIUM

SPIP <3.1.11 & <3.2.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-16394. PoCs published by trungnd51.

AI-analyzed exploit summary This repository contains a Python script that scans for valid email addresses vulnerable to CVE-2019-16394, an information disclosure vulnerability in SPIP. The script tests a list of emails against a target SPIP instance to identify valid accounts.

Description

SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

Exploits (1)

nomisec SCANNER
by trungnd51 · poc
https://github.com/trungnd51/Silent_CVE_2019_16394

This repository contains a Python script that scans for valid email addresses vulnerable to CVE-2019-16394, an information disclosure vulnerability in SPIP. The script tests a list of emails against a target SPIP instance to identify valid accounts.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: SPIP (version not specified)
No auth needed
Prerequisites: List of email addresses to test · Target SPIP instance URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://core.spip.net/issues/4171
Patch, Vendor Advisory x_refsource_misc
https://zone.spip.net/trac/spip-zone/changeset/117577/spip-zone
Patch, Vendor Advisory x_refsource_misc
https://zone.spip.net/trac/spip-zone/changeset/117578/spip-zone
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Sep/40
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4532
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/10/msg00038.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4536-1/

Scores

CVSS v3 5.3
EPSS 0.5674
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (5)
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
spip/spip < 3.1.11
Published Sep 17, 2019
Tracked Since Feb 18, 2026