
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability CVE-2020-15132 affects Sulu's password reset functionality in versions <1.6.35, <2.0.10, and <2.1.1. The vulnerability was discovered and disclosed in August 2020, impacting the authentication system of the Sulu content management system (GitHub Advisory).
The vulnerability consists of multiple related issues in the 'Forget password' feature. When this feature is used, the system responds differently based on whether a username exists, including returning a 400 error code with a specific error message for non-existent users. Additionally, the system exposes email addresses in successful password reset responses and exhibits timing differences in login attempts based on username existence. The reset token in the user database table is stored without hashing, potentially exposing sensitive information if database access is compromised (GitHub Advisory).
The vulnerability allows attackers to enumerate valid usernames through multiple vectors: the forget password feature's error messages, exposed email addresses in successful password reset responses, and timing differences in login attempts. If an attacker gains database access, they could also potentially exploit unhashed reset tokens (GitHub Advisory).
The vulnerability can be exploited through the application's user interface by utilizing the forget password feature and analyzing response patterns. No special privileges are required to exploit this vulnerability, making it accessible to any attacker who can access the login screen (GitHub Advisory).
The vulnerability was patched in Sulu versions 1.6.35, 2.0.10, and 2.1.1. For users unable to update immediately, a workaround involves manually overriding the affected files in their project and implementing appropriate changes (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."