CVE-2019-12743
MEDIUMHumHub Social Network Kit Enterprise 1.3.13 - User Enumeration via Username Brute-Force
Title source: llmDescription
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.
References (2)
Core 2
Core References
Product, Release Notes x_refsource_misc
https://humhub.org/en/news
Third Party Advisory x_refsource_misc
https://github.com/chanpu9/CVE/blob/master/2019-12743
Scores
CVSS v3
5.3
EPSS
0.0150
EPSS Percentile
71.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (1)
humhub/social_network_kit
1.3.13
Published
Jul 29, 2019
Tracked Since
Feb 18, 2026