First published: Wed Oct 16 2024(Updated: )
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usermin |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44762 is considered a medium severity vulnerability as it allows attackers to enumerate valid user accounts.
To fix CVE-2024-44762, update to the latest version of Webmin Usermin that addresses this error message discrepancy.
CVE-2024-44762 affects Webmin Usermin by allowing attackers to exploit incorrect error messages to discover valid user accounts.
All users of Webmin Usermin v2.100 are affected by CVE-2024-44762 due to the enumeration issue.
Attackers can use CVE-2024-44762 to enumerate valid user accounts, potentially leading to further attacks on the system.