5

CVE-2009-1803

FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Data is provided by the National Vulnerability Database (NVD)
FreepbxFreepbx Version2.4
FreepbxFreepbx Version2.4.0_beta1
FreepbxFreepbx Version2.4.0_beta2
FreepbxFreepbx Version2.4.1
FreepbxFreepbx Version2.5
FreepbxFreepbx Version2.5.0_beta1
FreepbxFreepbx Version2.5.0rc2
FreepbxFreepbx Version2.5.0rc3
FreepbxFreepbx Version2.5.1
FreepbxFreepbx Version2.5.2
SangomaFreepbx Version2.4.0
SangomaFreepbx Version2.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.519
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.