Oct. 10, 2023, 10:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

attack attacker brute cve enumeration found issue messages password password recovery recovery scheduler user enumeration valid

SITEC - Pen Tester

@ Peraton | MacDill AFB, FL, United States

Information Security Specialist (Sr. OT Security Engineer)

@ Vertiv | Philippines

Product Security Engineer

@ Anduril | Costa Mesa, California, United States

Cybersecurity Tools Engineer

@ Uni Systems | Mons, Wallonia, Belgium

Baseband Security Lead

@ Babcock | Corsham, GB, SN13 9NP

Cyber Network Defense Analyst III

@ KBR, Inc. | VA149: 1110 N Glebe Road Arlington 1110 North Glebe Road Suite 630, Arlington, VA, 22201 USA