CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.7. See the original NVD description below for full technical details.
CVE
CVE-2025-67807
Severity
MEDIUM
CVSS
4.7
EPSS
0.14%
Original NVD Description
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer versions.
Related CVEs
Other vulnerabilities affecting the same vendor(s)