CVE-2020-36888
EUVD-2020-3084110.12.2025, 21:16
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| spinetix | fusion_digital_signage | 𝑥 ≤ 3.4.8 |
𝑥
= Vulnerable software versions
References