Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different error messages for invalid users (user_not_found) versus valid users with incorrect passwords (invalid_password). This observable response discrepancy allows unauthenticated attackers to enumerate valid usernames on the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2025-65899, a user enumeration vulnerability in Kalmia CMS v0.2.0. The vulnerability arises from the authentication endpoint (/kal-api/auth/jwt/create) returning different error messages for non-existent users ('user_not_found') and valid users with incorrect passwords ('invalid_password'). The main exploit script, cve-2025-65899.py, is a Python 3 tool that automates the process of sending authentication requests to the vulnerable endpoint. It supports both single-user testing and bulk enumeration using a wordlist. The script analyzes the server's JSON responses to determine which usernames are valid, thus enabling attackers to enumerate users without authentication. The repository also includes a README.md with detailed vulnerability and exploitation information, and a requirements file listing dependencies (requests, colorama). The exploit is a network-based proof-of-concept and does not provide post-exploitation capabilities beyond user enumeration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.