There is a username enumeration via local user login in...
Low severity
Unreviewed
Published
Dec 17, 2025
to the GitHub Advisory Database
•
Updated Jan 5, 2026
Description
Published by the National Vulnerability Database
Dec 17, 2025
Published to the GitHub Advisory Database
Dec 17, 2025
Last updated
Jan 5, 2026
There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an OTP code and new password then reviewing application responses.
References