exploit to check for an existence of the user with specified username

XMLWordPrintable

    • Sprint 66 (Jul 2020), Sprint 67 (Aug 2020), Sprint 68 (Sep 2020), Sprint 69 (Oct 2020), Sprint 70 (Nov 2020)
    • 0.75

      Hi,

      I've just found minor security vulnerability:

      When you try to login to zabbix with incorrect password several time you'll soon get 'Account is blocked for XX seconds' message.
      However when you try this with non-existant account you receive no such kind of message.

      Thus you can check if the account with specified mail exists in the system.

            Assignee:
            Miks Kronkalns
            Reporter:
            Timur Batyrshin
            Team B
            Votes:
            6 Vote for this issue
            Watchers:
            12 Start watching this issue

              Created:
              Updated:
              Resolved: