PT-2025-39521 · Wso2 · Wso2 Products

Published

2025-09-26

·

Updated

2025-09-26

·

CVE-2025-1396

CVSS v3.1
3.7
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

**Name of the Vulnerable Software and Affected Versions**

WSO2 products (affected versions not specified)

**Description**

A username enumeration issue exists when Multi-Attribute Login is enabled. The system provides a different response for existing and non-existing usernames, regardless of the `validate username` setting. This allows attackers to determine valid usernames, potentially aiding in brute-force attacks, phishing, or social engineering. The API endpoint involved is the login form. The `username` parameter is vulnerable to enumeration.

**Recommendations**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2025-1396

Affected Products

Wso2 Products