PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-25350 UserSpice CVE debrief

CVE-2018-25350 documents a username enumeration vulnerability in userSpice 4.3.24. The issue resides in the existingUsernameCheck.php endpoint, which allows unauthenticated attackers to determine valid usernames by submitting POST requests and analyzing response content for the string 'taken'. This information disclosure weakness enables systematic account discovery without authentication credentials. The vulnerability was published on 2026-05-23 and last modified on 2026-05-26. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no required privileges, and high impacts to confidentiality, integrity, and availability. The weakness is classified as CWE-204 (Observable Response Discrepancy).

Vendor
UserSpice
Product
Unknown
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-23
Original CVE updated
2026-10-06
Advisory published
2026-05-23
Advisory updated
2026-10-06

Who should care

Organizations running userSpice 4.3.24 or earlier versions; security teams responsible for web application security; identity and access management administrators concerned with account enumeration risks; compliance teams addressing information disclosure vulnerabilities

Technical summary

The existingUsernameCheck.php endpoint in userSpice 4.3.24 returns distinguishable responses based on username existence. When a POST request is submitted with an existing username, the response contains the string 'taken', while non-existent usernames produce different responses. This observable discrepancy allows unauthenticated remote attackers to iteratively query the endpoint and compile lists of valid user accounts. The vulnerability requires no authentication, no user interaction, and is exploitable over the network with minimal complexity.

Defensive priority

HIGH

Recommended defensive actions

  • Implement rate limiting on the existingUsernameCheck.php endpoint to mitigate automated enumeration attempts
  • Configure web application firewall rules to detect and block patterns indicative of systematic username enumeration
  • Review and modify the endpoint response behavior to return identical responses regardless of username existence
  • Consider implementing CAPTCHA or similar challenge-response mechanisms for unauthenticated endpoint access
  • Audit access logs for historical exploitation attempts targeting the affected endpoint
  • Apply vendor patches when available or consider upgrading to a non-vulnerable version of userSpice

Evidence notes

The vulnerability description is derived from official NVD source data with references to Exploit-DB and VulnCheck advisories. Vendor attribution is marked as low confidence requiring review, with 'Unknown Vendor' placeholder and 'Exploit Db' as the reference domain candidate.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-25350 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-25350

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-25350 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-25350

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.