CVE-2025-55342 describes an information disclosure vulnerability in Quipux 4.0.1 through e1774ac. This flaw allows unauthenticated attackers to enumerate usernames and retrieve Ecuadorean identification numbers for all registered users by manipulating the 'txt_login' parameter in the 'Administracion/usuarios/cambiar_password_olvido_validar.php' endpoint. The vulnerability carries a CVSS score of 5.3 (Medium), indicating a low attack complexity and no user interaction required, with a potential impact of partial confidentiality loss. There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. It is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.1CPE matchmatch criteria | cpe:2.3:a:quipux:quipux:4.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.