Vulnerabilities > CVE-2020-9389 - Information Exposure Through Discrepancy vulnerability in Squaredup 4.6

047910
CVSS 3.7 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
high complexity
squaredup
CWE-203

Summary

A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.

Vulnerable Configurations

Part Description Count
Application
Squaredup
2

Common Weakness Enumeration (CWE)