Get Demo
An issue in the component routeuser.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.