CVE Feed

    Dashboard / CVE / CVE-2025-55795

    CVE-2025-55795

    The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a higher user ID without proper verification. This results in the victim's email being reassigned to the attacker's account, causing the victim to be locked out immediately and unable to log in. The vulnerability leads to denial of service via account lockout but does not grant the attacker direct access to the victim's private data.

    Published:Sep 29, 2025
    Last Modified:Oct 16, 2025
    EPS:Sep 29, 2025
    EPSS Score:0.00028
    CVSS Score:3.5

    Affected Products

    Vendor
    Openml
    Product
    Openml
    Vendor
    Openml
    Product
    Openml.org

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High