Skip to main content

Threats Tagged 'cwe-203'

View all threats tagged with 'cwe-203'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-203

Threats Tagged 'cwe-203'

Click on any threat for detailed analysis and mitigation recommendations

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames within the system. The impact is amplified for accounts that have not configured a mobile number, as the enumeration is specifically tied to this condition. The discovery of these usernames can facilitate subsequent brute force attacks, social engineering attempts, and information leakage, potentially leading to reputational damage, loss of customer trust, and regulatory non-compliance.

Join the discussion

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username is already in use. This behavior allows an attacker to discover valid usernames within the system. The discovery of valid usernames can facilitate subsequent attacks such as brute force, social engineering, and targeted phishing campaigns.

Join the discussion

Maravel PHP framework versions prior to 10.73.1 have a side-channel information disclosure vulnerability. When routes with dynamic placeholders are compiled, literal placeholder syntax can cause a 500 Internal Server Error instead of a 404 Not Found. This behavior allows an attacker to infer internal route parameter names and controller schemas by observing which inputs trigger errors. Version 10.73.1 includes a patch for this issue. A recommended workaround is to implement middleware that rejects requests containing literal brace patterns before routing.

Join the discussion
0

WatchGuard Dimension version 2.0 has a vulnerability in its web login endpoint where effective rate-limiting or account lockout is not enforced by default. This allows a remote attacker to perform automated password guessing attacks against user accounts. While an account lockout setting exists to block brute-force attempts after a defined number of failures, it is not enabled by default.

Join the discussion

CVE-2026-11754 is an observable discrepancy vulnerability in Seres Software syWEB that allows account footprinting. The product is no longer supported by the vendor. The vulnerability has a medium severity with a CVSS score of 5.3, indicating it can be exploited remotely without privileges or user interaction to gain limited information disclosure. No patch or remediation is currently available.

Join the discussion

Weblate versions prior to 2026.7 have an information disclosure vulnerability where unauthorized users can infer the existence of objects in private projects due to differing HTTP response codes (403 vs 404). This discrepancy allows attackers to confirm whether certain objects exist without access. The issue is fixed in version 2026.7.

Join the discussion

The Grav Login plugin before version 3.9.1 has an email address enumeration vulnerability. The register() method throws a distinct exception when an email is already registered, allowing attackers to confirm existing accounts. There is no rate limiting on the registration endpoint, enabling automated enumeration attacks.

Join the discussion

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored field that holds the value, and evaluated them with Kibana's own internal Elasticsearch privileges rather than the caller's. Because the number of matching agents is reported back to the caller, the difference between a matching and a non-matching filter formed a side channel from which the full API key value could be reconstructed one character at a time with a short sequence of requests.

Join the discussion

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Join the discussion

: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

Join the discussion

Showing 1 to 10 of 42 results

Filters:Tag: cwe-203
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses