CVE-2024-44762 is a username enumeration vulnerability affecting Webmin Usermin v2.100. This flaw allows attackers to distinguish between valid and invalid user accounts based on differing error messages during login attempts. With a CVSS score of 5.3 (Medium), it presents a low-complexity network attack that could lead to information disclosure (user enumeration) without requiring user interaction or privileges. While not currently listed in CISA's KEV catalog, public exploit code and Nuclei templates are available, indicating a clear path for potential exploitation, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.100CPE matchmatch criteria | cpe:2.3:a:webmin:usermin:2.100:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.