https://nvd.nist.gov/vuln/detail/CVE-2025-56132

"You can enumerate email addresses by sending a request to password_reset with different test emails and seeing how the server responds"

so we're assigning CVEs to basic HTB tricks now huh?

NVD - CVE-2025-56132

@Dio9sys All that's old is new again (when half the industry started using computers yesterday via the slop machine).
@Dio9sys Seriously? I've been waiting for mitre to take action on a CVE I requested for an unauthenticated RCE in August 2025, but this gets published?