vendor:
SpinetiX Fusion Digital Signage
by:
LiquidWorm
5.5
CVSS
MEDIUM
Username Enumeration
209
CWE
Product Name: SpinetiX Fusion Digital Signage
Affected Version From: <= 3.4.8
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:spinetix:fusion_digital_signage:3.4.8
Platforms Tested: Linux
2020
SpinetiX Fusion Digital Signage 3.4.8 – Username Enumeration
The weakness is caused due to the login script and how it verifies provided credentials. Attacker can use this weakness to enumerate valid users on the affected node.
Mitigation:
Implement proper username and password validation to prevent enumeration attacks.