Username Enumeration Vulnerability in userSpice by userSpice
CVE-2018-25350
Key Information:
Badges
What is CVE-2018-25350?
The userSpice 4.3.24 version is affected by a username enumeration vulnerability that allows attackers without authentication to identify valid usernames. By interacting with the existingUsernameCheck.php endpoint using POST requests, attackers can gather information by analyzing the responses for the presence of the 'taken' string. This vulnerability can be exploited to facilitate further attacks or unauthorized access to user accounts, emphasizing the need for robust security measures.
Affected Version(s)
userSpice 4.3.24
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
