Vulnerability Description
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Humhub | Social Network Kit | 1.3.13 |
Related Weaknesses (CWE)
References
- https://github.com/chanpu9/CVE/blob/master/2019-12743Third Party Advisory
- https://humhub.org/en/newsProductRelease Notes
- https://github.com/chanpu9/CVE/blob/master/2019-12743Third Party Advisory
- https://humhub.org/en/newsProductRelease Notes
FAQ
What is CVE-2019-12743?
CVE-2019-12743 is a vulnerability with a CVSS score of 5.3 (MEDIUM). HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the ...
How severe is CVE-2019-12743?
CVE-2019-12743 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12743?
Check the references section above for vendor advisories and patch information. Affected products include: Humhub Social Network Kit.