NetEpi Case Manager before 0.98 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netepi_case_manager | Netepi_case_manager | 0.96 | 0.96 |
Netepi_case_manager | Netepi_case_manager | 0.94 | 0.94 |
Netepi_case_manager | Netepi_case_manager | 0.95 | 0.95 |
Netepi_case_manager | Netepi_case_manager | 0.97 | 0.97 |
Netepi_case_manager | Netepi_case_manager | 0.93 | 0.93 |