Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Sage DPW 安全漏洞
Vulnerability Description
Sage DPW是英国Sage公司的一个人力资源系统。 Sage DPW 2021_06_004版本存在安全漏洞,该漏洞源于登录机制对有效和无效用户名显示不同响应,可能导致在2021_06_000之前版本中枚举现有账户。
CVSS Information
N/A
Vulnerability Type
N/A