User Enumeration Vulnerability in Citrix XenApp by Citrix
CVE-2020-13998
5.3MEDIUM
What is CVE-2020-13998?
A vulnerability in Citrix XenApp 6.5 allows remote unauthenticated attackers to determine whether a user exists on the server when two-factor authentication (2FA) is enabled. This occurs due to the behavior of the 2FA error page, which is displayed only after a valid username is entered. As a result, attackers can exploit this mechanism to enumerate valid user accounts, posing a significant security risk. Note that this vulnerability affects products that are no longer maintained by Citrix.