CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Corporatetime_for_the_web | Csandt | * | 2.1.2 (including) |