CVE-2024-44762
48Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 5.3epss 2.6%
from disclosure to weapon169 days
Published on NVDOct 16
1st PoC+169d
exploitation probability
2.6%top 16% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/52254unverifiedexploitdbwww.exploit-db.com/exploits/52114unverifiedgithubgithub.com/arbaaz29/CVE-2024-44762-webmin-userenum★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.