Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
0.0.0 (semver) before 2.3.3
affected
Description
The web application allows an unauthenticated remote attacker to learn information about existing user accounts with their corresponding role due to missing authentication for critical function.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
0.0.0 (semver) before 2.3.3
References
certvde.com/de/advisories/VDE-2025-087