#VU17727 Information disclosure in JForum - CVE-2019-7550

 

#VU17727 Information disclosure in JForum - CVE-2019-7550

Published: February 16, 2019 / Updated: March 7, 2021


Vulnerability identifier: #VU17727
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2019-7550
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
JForum
Software vendor:
jforum.net

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists in the create user function due to the way the software handles messages based on username validity. A remote attacker can send mass register/check/username?username= requests to access sensitive information, such as valid usernames, to enumerate within the customer environment.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links