Summary

Acunetix 360 identified a Windows Username Disclosure in the error message.

Impact

An attacker can perform brute-force or dictionary-based password guessing on the disclosed username. It may also help the attacker identify other vulnerabilities or further their exploitation of other identified vulnerabilities.

Remediation

  • Error messages should be disabled.
  • Remove this kind of sensitive data from the output.

Severity

Low

Classification

PCI v3.2-6.5.5 CAPEC-118 CWE-200 ISO27001-A.18.1.3 WASC-13 OWASP 2013-A6 OWASP 2017-A3