CVE-2025-46047
02.09.2025, 14:15
A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.Enginsight
Vendor | Product | Version |
---|---|---|
silverpeas | silverpeas | 6.4.1 |
silverpeas | silverpeas | 6.4.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration