SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-12743

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy…

MEDIUM 5.3EPSS 1.50%

Does this matter?

Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.

Description

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.50% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
humhub/social network kit
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.