PT-2025-4853 · Unknown · Cosmos-Server

·

CVE-2025-23214

·

Published

2025-01-20

·

Updated

2025-01-20

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Cosmos-Server versions prior to 0.17.7
Description The Cosmos-Server software has a user enumeration issue due to the error code returned during login, allowing an attacker to determine if a user exists in the database by monitoring the error code.
Recommendations For Cosmos-Server versions prior to 0.17.7, update to version 0.17.7 to resolve the issue. As a temporary workaround, consider restricting access to the login functionality until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23214
GHSA-5843-2P4F-57FH

Affected Products

Cosmos-Server