CVE-2019-7550 Information
Feb 14, 2021
cve
Description
In JForum 2.1.8 an unauthenticated remote attacker can enumerate whether a user exists by using the \create user\ function. If a register/check/username?username= request corresponds to a username that exists then an \is already in use\ error is produced. NOTE: this product is discontinued.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://www.criticalstart.com/2019/02/information-disclosure-in-jforum-2-1-x-syntax/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: