MEDIUM🇵🇱 Wersja polska

CVE-2026-25222

CVSS 6.3v4.0pub. 2026-02-02upd. 2026-02-20

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in the sign-in process allows unauthenticated attackers to determine if a specific email address is registered on the platform. By measuring the response time of the login endpoint, an attacker can distinguish between valid and invalid email addresses. This occurs because the server only performs the computationally expensive Argon2 password hashing if the user exists in the database. Requests for existing users take significantly longer (~650ms) than requests for non-existent users (~160ms).

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Polarlearn

    APP
    Polarlearn
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-39322CRITICAL9.2PL ✓same product

PolarLearn: Pominięcie weryfikacji hasła przy logowaniu zbanowanych kont

CVE-2026-25885CRITICAL10.0PL ✓same product

PolarLearn: brak uwierzytelnienia w WebSocket czatu grupowego

CVE-2026-35610HIGH8.8same product

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userI...

CVE-2026-25126HIGH7.1same product

PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`...

CVE-2026-25221LOW2.3same product

PolarLearn to darmowy program edukacyjny o otwartym kodzie źródłowym. W wersji 0-PRERELEASE-15 i wcześniejszyc...