The login mechanism of Sage DPW 2021_06_004 displays...
Low severity
Unreviewed
Published
Apr 1, 2026
to the GitHub Advisory Database
•
Updated Apr 7, 2026
Description
Published by the National Vulnerability Database
Apr 1, 2026
Published to the GitHub Advisory Database
Apr 1, 2026
Last updated
Apr 7, 2026
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.
References