Severity

7.5

Vulnerability Type

Observable Discrepancy (CWE-203)

Summary

In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by checking what kind of response the server sends.

Impact

no impact information found