Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8ch-45q6-53xj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

EPSS

Процентиль: 47%
0.00244
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 5.3
nvd
больше 6 лет назад

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

EPSS

Процентиль: 47%
0.00244
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200
CWE-203