CVE-2018-25350
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| UserSpice | userSpice | — | 4.3.24 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-204 | cna | Observable Response Discrepancy |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (2)
- ExploitDB-44872 https://www.exploit-db.com/exploits/44872
- VulnCheck Advisory: userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php https://www.vulncheck.com/advisories/userspice-username-enumeration-via-existingusernamecheck-php