CVE-2019-12743

MEDIUM

HumHub Social Network Kit Enterprise 1.3.13 - User Enumeration via Username Brute-Force

Title source: llm
STIX 2.1

Description

HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.

References (2)

Core 2
Core References
Product, Release Notes x_refsource_misc
https://humhub.org/en/news

Scores

CVSS v3 5.3
EPSS 0.0150
EPSS Percentile 71.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-203
Status published
Products (1)
humhub/social_network_kit 1.3.13
Published Jul 29, 2019
Tracked Since Feb 18, 2026