自注册流程在接收用户输入的用户名时,未能有效防止用户名的存在性泄露。当用户尝试使用已存在的用户名进行注册时,系统会返回一条明确提示该用户名已被占用的错误消息。 这种行为使得攻击者能够发现系统中有效的用户名。发现有效用户名有助于发起后续攻击,例如暴力破解、社会工程学攻击以及定向钓鱼攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WSO2 | WSO2 API Manager | 3.1.0 ~ 3.1.0.354 | - |
|
| WSO2 | WSO2 API Control Plane | 4.5.0 ~ 4.5.0.56 | - |
|
| WSO2 | WSO2 Universal Gateway | 4.5.0 ~ 4.5.0.55 | - |
|
| WSO2 | WSO2 Traffic Manager | 4.5.0 ~ 4.5.0.54 | - |
|
| WSO2 | WSO2 Identity Server | 5.10.0 ~ 5.10.0.383 | - |
|
| WSO2 | WSO2 Identity Server as Key Manager | 5.10.0 ~ 5.10.0.374 | - |
|
| WSO2 | WSO2 Open Banking AM | 2.0.0 ~ 2.0.0.403 | - |
|
| WSO2 | WSO2 Open Banking IAM | 2.0.0 ~ 2.0.0.423 | - |
|
| WSO2 | WSO2 Carbon Identity Management Endpoint Util | 5.17.5 ~ 5.17.5.332 | - |
|
| WSO2 | WSO2 Carbon Identity Application Authentication Framework | 5.17.5 ~ 5.17.5.332 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19515 | 7.0 HIGH | OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allow |
| CVE-2025-13166 | 3.7 LOW | Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discover |
No comments yet