MantisBT - CDash
View Issue Details
0013577CDashpublic2012-10-06 06:552012-10-18 03:17
Jonnycake 
Julien Jomier 
normalminoralways
resolvedfixed 
 
2.2 
0013577: User Enumeration Vulnerability
User enumeration would allow an attacker to discover emails in the database.
Input valid username/valid password: functions as expected.
Input valid username/invalid password: displays "Wrong username or password."
Input invalid username: displays "This user doesn't exist."
Quick fix, just change the text you display when an invalid username is input to that of a valid username/invalid password.
No tags attached.
Issue History
2012-10-06 06:55JonnycakeNew Issue
2012-10-18 03:11Julien JomierAssigned To => Julien Jomier
2012-10-18 03:11Julien JomierStatusnew => assigned
2012-10-18 03:17Julien JomierNote Added: 0031256
2012-10-18 03:17Julien JomierStatusassigned => resolved
2012-10-18 03:17Julien JomierFixed in Version => 2.2
2012-10-18 03:17Julien JomierResolutionopen => fixed

Notes
(0031256)
Julien Jomier   
2012-10-18 03:17   
Thanks a lot for the report.