Usermin version 2.100 and below is susceptible to username enumeration via the password change functionality. An attacker can determine valid usernames by analyzing the response messages from the password change endpoint.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view