Bug 2439622 (CVE-2019-25338) - CVE-2019-25338 dokuwiki: DokuWiki: Information disclosure through username enumeration in password reset
Summary: CVE-2019-25338 dokuwiki: DokuWiki: Information disclosure through username en...
Keywords:
Status: NEW
Alias: CVE-2019-25338
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2439689
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-13 00:02 UTC by OSIDB Bzimport
Modified: 2026-02-13 14:18 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-13 00:02:05 UTC
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.


Note You need to log in before you can comment on or make changes to this bug.