mtons mblog
cpe:2.3:a:mblog_project:mblog:*:*:*:*:*:*:*
- <= 3.5.0
An information exposure vulnerability has been identified in Mtons Mblog versions through 3.5.0. The issue arises in an unknown function of the file '/register', where error messages inadvertently reveal whether a username already exists. This flaw allows for username enumeration and could be exploited to perform batch account registrations. The vulnerability can be exploited remotely, but the complexity of the attack is considered high.
Exploitation of this vulnerability leads to unauthorized information disclosure, specifically through error messages that reveal sensitive information about the application's user registration process.
To reproduce this vulnerability, access the '/register' endpoint of the Mtons Mblog application. The endpoint lacks CAPTCHA protection and rate limiting. Submit registration requests with various usernames. The response will indicate whether each username is available or already taken, allowing for enumeration of existing usernames. This process can be automated to facilitate batch account registration.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.