userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
UserSpice · userSpicepublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/44872unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.