NetEpi Case Manager before 0.98 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netepi_case_manager | Netepi_case_manager | 0.93 (including) | 0.93 (including) |
Netepi_case_manager | Netepi_case_manager | 0.94 (including) | 0.94 (including) |
Netepi_case_manager | Netepi_case_manager | 0.95 (including) | 0.95 (including) |
Netepi_case_manager | Netepi_case_manager | 0.96 (including) | 0.96 (including) |
Netepi_case_manager | Netepi_case_manager | 0.97 (including) | 0.97 (including) |