Description
The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical function.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
0.0.0 (semver) before 2.3.3
References
certvde.com/de/advisories/VDE-2025-087