CVE-2023-53943
GLPI vulnerability analysis and mitigation

Overview

CVE-2023-53943 is a username enumeration vulnerability in GLPI 9.5.7's lost password recovery mechanism, classified as an Observable Discrepancy (CWE-203). It allows unauthenticated remote attackers to validate whether email addresses correspond to valid user accounts by analyzing response differences from the password reset endpoint. The CVE was assigned by VulnCheck and published on December 18, 2025. It affects specifically GLPI version 9.5.7. The CVSS v3.1 base score is 5.3 (Medium) and the CVSS v4.0 base score is 6.9 (Medium) (VulnCheck Advisory, Red Hat CVE).

Technical details

The root cause is an Observable Discrepancy (CWE-203) in GLPI's password reset endpoint, where the application returns distinguishably different responses depending on whether a submitted email address corresponds to a registered user account. This information leakage allows an attacker to systematically enumerate valid user accounts without any authentication or special privileges. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to automate. A public exploit is available on Exploit-DB (EDB-51418) demonstrating the enumeration technique (VulnCheck Advisory, Exploit-DB).

Impact

Successful exploitation results in a limited confidentiality impact — specifically, the disclosure of valid user email addresses registered in the GLPI instance. While there is no direct integrity or availability impact, the enumerated account information can be leveraged to support targeted phishing campaigns, credential stuffing, or brute-force attacks against identified accounts, potentially leading to unauthorized access to the IT asset management system. GLPI often contains sensitive organizational data including hardware inventories, helpdesk tickets, and user credentials, making account compromise a significant downstream risk (VulnCheck Advisory, Red Hat CVE).

Exploitability

A public proof-of-concept exploit is available on Exploit-DB (EDB-51418), referenced by both CISA-ADP and VulnCheck (Exploit-DB). The vulnerability is detectable via Nessus plugin 279431. The EPSS score is approximately 0.027% (0.000270), indicating a low but non-zero probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing GLPI 9.5.7 instances using search engines like Shodan or Censys, or by directly browsing to the GLPI login page which often reveals the version number.
  2. Locate the password reset endpoint: Navigate to the GLPI lost password recovery page, typically accessible at /index.php?lost_password=1 or a similar endpoint without authentication.
  3. Submit email addresses: Craft automated HTTP POST requests to the password reset endpoint, submitting candidate email addresses (e.g., from a wordlist or harvested from OSINT).
  4. Analyze response differences: Compare server responses for submitted addresses — differences in response body content, HTTP status codes, or response timing indicate whether an email address is registered in the system (Observable Discrepancy).
  5. Compile valid accounts: Collect confirmed valid email addresses for use in subsequent attacks such as phishing, credential stuffing, or targeted brute-force against the GLPI login (Exploit-DB, VulnCheck Advisory).

Indicators of compromise

  • Network: High volume of HTTP POST requests to the GLPI password reset endpoint (e.g., /index.php?lost_password=1) from a single IP or a distributed set of IPs in a short time window; requests containing systematically varied email addresses.
  • Logs: Web server access logs showing repeated requests to the lost password endpoint with different email parameters, particularly from automated user-agents or at unusual hours; abnormal request rates to the password reset functionality.
  • Application: GLPI application logs showing a large number of password reset attempts for non-existent or valid accounts in rapid succession.

Mitigation and workarounds

Users should upgrade GLPI beyond version 9.5.7 to a patched release that normalizes responses from the password reset endpoint regardless of whether the submitted email is valid. As a workaround, administrators can implement rate limiting and CAPTCHA on the password reset endpoint to slow automated enumeration attempts. Network-level controls such as WAF rules blocking high-frequency requests to the lost password endpoint can also reduce exposure. Monitoring for anomalous request patterns to the password reset functionality is recommended as a detective control (VulnCheck Advisory, GLPI Project).

Additional resources


SourceThis report was generated using AI

Related GLPI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-42321HIGH8.4
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-44281HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-42318HIGH7
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026
CVE-2026-13490MEDIUM6.3
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 28, 2026
CVE-2026-42320MEDIUM5.9
  • GLPI logoGLPI
  • cpe:2.3:a:glpi-project:glpi
NoYesJun 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management