https://nvd.nist.gov/vuln/detail/CVE-2025-56132

"You can enumerate email addresses by sending a request to password_reset with different test emails and seeing how the server responds"

so we're assigning CVEs to basic HTB tricks now huh?

NVD - CVE-2025-56132

@Dio9sys Seriously? I've been waiting for mitre to take action on a CVE I requested for an unauthenticated RCE in August 2025, but this gets published?