Description
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. Attackers can send requests with valid usernames to retrieve user information.
Problem types
CWE-204: Observable Response Discrepancy
Product status
2.5.9.6
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50164 (ExploitDB-50164)
www.eforcesoftware.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5658.php (Zero Science Lab Disclosure (ZSL-2021-5658))
www.vulncheck.com/...rce-software-suite-username-enumeration (VulnCheck Advisory: IntelliChoice eFORCE Software Suite Username Enumeration)