ABB Cylon Aspect 3.08.01 jsonProxy.php Username Enumeration

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 is vulnerable to username enumeration in the jsonProxy.php endpoint. An unauthenticated attacker can interact with the UserManager servlet to enumerate valid usernames on the system. Since jsonProxy.php proxies requests to internal services without requiring authentication, attackers can gain unauthorized insights into valid usernames.

    Continue reading...
     

Share This Page

Loading...