vendor:
eFORCE Software Suite
by:
LiquidWorm
4,3
CVSS
MEDIUM
Username Enumeration
200
CWE
Product Name: eFORCE Software Suite
Affected Version From: 2.5.9.6
Affected Version To: 2.5.3.11
Patch Exists: NO
Related CWE: N/A
CPE: a:intellichoice:eforce_software_suite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft-IIS/10.0, Microsoft-IIS/8.5, ASP.NET/4.0.30319
2021
IntelliChoice eFORCE Software Suite 2.5.9 – Username Enumeration
The weakness is caused due to the login script and how it verifies provided credentials. Attacker can use this weakness to enumerate valid users on the affected application via 'ctl00$MainContent$UserName' POST parameter.
Mitigation:
Ensure that the application does not provide any information about the existence of a user account.