在短信一次性密码(OTP)验证流程中,错误消息的处理不够完善,使得攻击者能够根据发起 OTP 流程时收到的响应,推断出哪些用户账号是已注册的。 该弱点可被攻击者利用来发现系统内有效的用户名。对于未绑定手机号码的账号,这种枚举效应尤为明显,因为该漏洞与“未配置手机号”这一条件直接相关。这些用户名的发现可能为后续的暴力破解攻击、社会工程学尝试和信息泄露提供便利,进而可能导致声誉受损、客户信任度下降以及不符合监管合规要求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 Identity Server | 7.1.0 ~ 7.1.0.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19515 | 7.0 HIGH | OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allow |
| CVE-2025-5802 | 5.3 MEDIUM | Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Acco |
No comments yet