In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.
References
Link | Resource |
---|---|
https://www.criticalstart.com/2019/02/information-disclosure-in-jforum-2-1-x-syntax/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-02-12 20:29
Updated : 2024-02-04 20:03
NVD link : CVE-2019-7550
Mitre link : CVE-2019-7550
CVE.ORG link : CVE-2019-7550
JSON object : View
Products Affected
jforum
- jforum
CWE
CWE-209
Generation of Error Message Containing Sensitive Information