Skip to content

Login enumerates user accounts

High
glye published GHSA-q3x8-6898-23g3 Oct 17, 2025

Package

composer ibexa/user (Composer)

Affected versions

v5.0.*

Patched versions

v5.0.3

Description

Impact

In v5, error messages could provide enough information to tell whether a user exists or not. This is resolved by ensuring the error messages are sufficiently ambigious.

Patches

See "Patched versions".

Workarounds

None.

References

https://developers.ibexa.co/security-advisories/ibexa-sa-2025-004-xss-and-enumeration-vulnerabilities-in-back-office

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs