CVE-2025-54791Medium· 5.3▾ SunlitOMERO.web displays unecessary user information when requesting password reset
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.3%
If an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user.
OMERO.web before 5.29.1
User should upgrade to 5.29.2 or higher
Disable the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property1.
Thanks to Christopher Youd who reported the issue.
Open an issue in omero-web Email us at [email protected]
omero-web < 5.29.2Upgrade to a patched release:
omero-web 5.29.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.