This exploit performs username enumeration in UserSpice 4.3.24 by checking if a username is taken via a POST request to the existingUsernameCheck.php endpoint. It reads usernames from a file and checks each one against the target system.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:UserSpice 4.3.24
No auth needed
Prerequisites:Target IP address · List of usernames in a text file