vendor:
Usermin
by:
Kjesper
4.1
CVSS
MEDIUM
Username Enumeration
200
CWE
Product Name: Usermin
Affected Version From: <= 2.100
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2024-44762
CPE: a:webmin:usermin:2.100
Platforms Tested: Kali Linux
2024
Usermin 2.100 – Username Enumeration
Usermin version 2.100 allows an attacker to enumerate valid usernames by sending requests to the password_change.cgi endpoint. By observing the responses, an attacker can identify valid usernames on the system.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to the password_change.cgi endpoint and implement account lockout mechanisms to prevent username enumeration.