CVE-2025-65899
MEDIUMKalmia 0.2.0 - Unauthenticated User Enumeration via Authentication Error Messages
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-65899. PoCs published by Noxurge.
AI-analyzed exploit summary The repository contains a functional PoC for CVE-2025-65899, which exploits an observable response discrepancy in Kalmia CMS v0.2.0 to enumerate valid usernames. The script automates the process by analyzing server responses to distinguish between non-existent and valid user accounts.
Description
Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_password). This observable response discrepancy allows unauthenticated attackers to enumerate valid usernames on the system.
Exploits (1)
The repository contains a functional PoC for CVE-2025-65899, which exploits an observable response discrepancy in Kalmia CMS v0.2.0 to enumerate valid usernames. The script automates the process by analyzing server responses to distinguish between non-existent and valid user accounts.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N