User Enumeration Vulnerability in WSO2 Identity Server
CVE-2025-13166
3.7LOW
What is CVE-2025-13166?
The vulnerability in WSO2 Identity Server arises from improper handling of error messages during the SMS OTP flow. This flaw allows attackers to ascertain the existence of registered user accounts based on system responses when initiating OTP requests. If attackers target accounts without a configured mobile number, they can exploit this vulnerability even more easily, leading to the potential compromise of user accounts. This enumeration can facilitate further attacks, including brute force, social engineering, and information leaks, which could tarnish brand reputation and erode user trust.
Affected Version(s)
WSO2 Identity Server 7.1.0 < 7.1.0.40
WSO2 Identity Server 7.2.0 < 7.2.0.2
