User Enumeration

medium Web App Scanning Plugin ID 114947

Synopsis

User Enumeration

Description

The scanner has detected a potential user enumeration vulnerability in the web application. This vulnerability allows an attacker to determine valid usernames by observing the application's responses.

Solution

Ensure that user enumeration vulnerabilities are mitigated by implementing proper authentication mechanisms and generic error messages, rate limiting, and other techniques to prevent attackers from determining valid usernames.

See Also

https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html

Plugin Details

Severity: Medium

ID: 114947

Type: remote

Published: 9/3/2025

Updated: 9/3/2025

Scan Template: api, basic, full, overview, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 2.9

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information