Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31378 | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1. |
Fri, 03 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arandasoft
Arandasoft passrecovery |
|
| CPEs | cpe:2.3:a:arandasoft:passrecovery:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Arandasoft
Arandasoft passrecovery |
Mon, 29 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aranda
Aranda passrecovery |
|
| Vendors & Products |
Aranda
Aranda passrecovery |
Fri, 26 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 26 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-29T15:26:48.579Z
Reserved: 2025-04-22T00:00:00.000Z
Link: CVE-2025-45994
Updated: 2025-09-26T20:37:13.524Z
Status : Analyzed
Published: 2025-09-26T18:15:36.073
Modified: 2025-10-03T19:28:20.387
Link: CVE-2025-45994
No data.
OpenCVE Enrichment
Updated: 2025-09-29T09:31:12Z
EUVD