Description
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user by entering that user's email address.
Problem types
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
Product status
Any version before 15.08.2025
Credits
Jannik Zimmer
References
certvde.com/en/advisories/VDE-2025-050