CVE-2025-46047
MEDIUMSilverpeas 6.4.1-6.4.2 - User Enumeration via ForgotPassword Login Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-46047. PoCs published by J0ey17.
AI-analyzed exploit summary This PoC demonstrates a username enumeration vulnerability in Silverpeas <= 6.4.2 by exploiting observable response discrepancies in the forgot password functionality. The script sends POST requests with potential usernames and checks the HTTP status code to determine valid accounts.
Description
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.
Exploits (1)
This PoC demonstrates a username enumeration vulnerability in Silverpeas <= 6.4.2 by exploiting observable response discrepancies in the forgot password functionality. The script sends POST requests with potential usernames and checks the HTTP status code to determine valid accounts.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N