SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error responses.
| Software | From | Fixed in |
|---|---|---|
| spinetix / fusion_digital_signage | - | 3.4.8.x |