CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.7. See the original NVD description below for full technical details.
CVE
CVE-2025-67806
Severity
LOW
CVSS
3.7
EPSS
0.26%
Original NVD Description
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)