CVE-2025-9109
Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint.
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
- CVSS 4.0
- 2.9 LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203, CWE-204
- Affected
- portabilis/i-diario
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.320431Permissions Required, VDB Entry
- https://vuldb.com/?id.320431Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.627926Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.