Brute Force Vulnerability in HumHub Social Network Kit by HumHub
CVE-2019-12743
5.3MEDIUM
What is CVE-2019-12743?
The HumHub Social Network Kit Enterprise v1.3.13 is susceptible to a vulnerability that enables remote attackers to enumerate user accounts by systematically guessing usernames. This occurs through a flaw in the handling of specific URI patterns, which inadvertently reveals the existence of accounts based on the responses received during brute-force attempts. By exploiting this weakness, an attacker can determine valid usernames on the platform, posing significant privacy and security risks to users.
