Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-16394. PoCs published by trungnd51.
AI-analyzed exploit summary This repository contains a Python script that scans for valid email addresses vulnerable to CVE-2019-16394, an information disclosure vulnerability in SPIP. The script tests a list of emails against a target SPIP instance to identify valid accounts.
Description
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
Exploits (1)
This repository contains a Python script that scans for valid email addresses vulnerable to CVE-2019-16394, an information disclosure vulnerability in SPIP. The script tests a list of emails against a target SPIP instance to identify valid accounts.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N