CVE-2019-25338 Details
Description
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.
A username enumeration vulnerability has been identified in DokuWiki version 2018-04-22b. This issue arises within the password reset feature, allowing attackers to determine valid user accounts. By submitting various usernames to the password reset endpoint and analyzing the server's error response, attackers can distinguish between existing and non-existing accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.dokuwiki.org/ | [email protected] | Product |
| https://www.dokuwiki.org/dokuwiki | [email protected] | Product |
| https://www.exploit-db.com/exploits/47731 | [email protected] | ExploitVDB Entry |
| https://www.vulncheck.com/advisories/dokuwiki-b-username-enumeration | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-204 | Observable Response Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dokuwiki dokuwiki | 2018-04-22b |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | CVE Modified | [email protected] |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 12, 2026 | New CVE Received | [email protected] |