Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-41161

4 месяца назад

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This issue has been patched in version 2.2.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43fj-qp3h-hrh5

5 месяцев назад

Sync-in Server has Username Enumeration via Timing Attack

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-41161

Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This issue has been patched in version 2.2.0.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-43fj-qp3h-hrh5

Sync-in Server has Username Enumeration via Timing Attack

0%
Низкий
5 месяцев назад

Уязвимостей на страницу