Description
Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
before 27-06-2025
Credits
Humza Ahmad
Max van der Horst
References
csirt.divd.nl/CVE-2025-36759
csirt.divd.nl/DIVD-2025-00015