View Issue Details Jump to Notes ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0013577CDashpublic2012-10-06 06:552012-10-18 03:17
ReporterJonnycake 
Assigned ToJulien Jomier 
PrioritynormalSeverityminorReproducibilityalways
StatusresolvedResolutionfixed 
PlatformOSOS Version
Product Version 
Target VersionFixed in Version2.2 
Summary0013577: User Enumeration Vulnerability
DescriptionUser enumeration would allow an attacker to discover emails in the database.
Steps To ReproduceInput valid username/valid password: functions as expected.
Input valid username/invalid password: displays "Wrong username or password."
Input invalid username: displays "This user doesn't exist."
Additional InformationQuick fix, just change the text you display when an invalid username is input to that of a valid username/invalid password.
TagsNo tags attached.
Attached Files

 Relationships

  Notes
(0031256)
Julien Jomier (manager)
2012-10-18 03:17

Thanks a lot for the report.

 Issue History
Date Modified Username Field Change
2012-10-06 06:55 Jonnycake New Issue
2012-10-18 03:11 Julien Jomier Assigned To => Julien Jomier
2012-10-18 03:11 Julien Jomier Status new => assigned
2012-10-18 03:17 Julien Jomier Note Added: 0031256
2012-10-18 03:17 Julien Jomier Status assigned => resolved
2012-10-18 03:17 Julien Jomier Fixed in Version => 2.2
2012-10-18 03:17 Julien Jomier Resolution open => fixed


Copyright © 2000 - 2018 MantisBT Team