Q-Free MaxTime Missing Authorization Vulnerability in User Enumeration
Vulnerability
A missing authorization vulnerability has been identified in Q-Free MaxTime versions through 2.11.0. This vulnerability allows authenticated low-privileged attackers to enumerate users by sending crafted HTTP requests to the users endpoint.
Impact
Exploitation of this vulnerability could lead to user enumeration, allowing for brute-force or credential-stuffing attacks.
Remediation
No official solution has been communicated by the vendor. As a temporary measure, it is recommended to review all accounts on the management web application exposed by devices running Q-Free MaxTime through version 2.11.0 and delete any unnecessary accounts.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
