Back to overview

CVE-2018-25350

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system.

Metadata

CVE ID
CVE-2018-25350
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-05-23 15:34 UTC
Published
2026-05-23 18:30 UTC
Last updated
2026-05-26 13:27 UTC
Primary CWE
CWE-204
Observable Response Discrepancy
Vendor / Product
UserSpice / userSpice
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
UserSpice userSpice 4.3.24
Weakness (CWE)
CWESourceDescription
CWE-204 cna Observable Response Discrepancy
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (2)
Back to overview