datacycle-engine dataCycle-CORE
- <= 25.07.3
A user directory enumeration vulnerability has been identified in dataCycle-CORE versions prior to 25.07.3. In the core processing module, standard users can exploit the `/users/search` endpoint to retrieve the names and email addresses of other users. This occurs despite restrictions preventing direct access to those user profiles. As a result, internal staff email addresses, full names, and the existence of guest and external test accounts are inadvertently exposed.
Exploitation of this vulnerability allows standard users to enumerate the names and email addresses of other users, including internal staff and the existence of guest and external test accounts.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.