Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30433
HistoryMay 14, 2021 - 7:29 a.m.

User Enumeration

2021-05-1407:29:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
symfony
user enumeration
vulnerability
exception messages
response time.

EPSS

0.001

Percentile

47.8%

Symfony allows user enumeration. A remote attacker is able to discover existing and valid users due to different exception messages returned by the server, as well as the difference in server response time.