Vulnerability Description
IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. Attackers can send requests with valid usernames to retrieve user information.
Related Weaknesses (CWE)
References
- https://www.eforcesoftware.com
- https://www.exploit-db.com/exploits/50164
- https://www.vulncheck.com/advisories/intellichoice-eforce-software-suite-usernam
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5658.php
FAQ
What is CVE-2021-47717?
CVE-2021-47717 is a documented vulnerability. IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. At...
How severe is CVE-2021-47717?
CVSS scoring is not yet available for CVE-2021-47717. Check NVD for updates.
Is there a patch for CVE-2021-47717?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.