No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 26 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Userspice
Userspice userspice |
|
| Vendors & Products |
Userspice
Userspice userspice |
Sat, 23 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system. | |
| Title | userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-26T13:27:55.786Z
Reserved: 2026-05-23T15:34:00.756Z
Link: CVE-2018-25350
Updated: 2026-05-26T13:27:52.870Z
Status : Deferred
Published: 2026-05-23T19:16:55.120
Modified: 2026-05-26T19:37:32.587
Link: CVE-2018-25350
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:27Z