← Back to CVE List

CVE-2019-7550

Published: 2019-02-12T20:29Z
Last Modified: 2024-11-21T04:48Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt