Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32mh-8hmm-h86p

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

EPSS

Процентиль: 92%
0.07414
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 11 лет назад

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

EPSS

Процентиль: 92%
0.07414
Низкий

Дефекты

CWE-200