In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
                
            References
                    | Link | Resource | 
|---|---|
| https://logpoint.com | Product | 
| https://servicedesk.logpoint.com/hc/en-us/articles/18435146614301-Username-Enumeration-on-Shared-Widgets | Vendor Advisory | 
| https://logpoint.com | Product | 
| https://servicedesk.logpoint.com/hc/en-us/articles/18435146614301-Username-Enumeration-on-Shared-Widgets | Vendor Advisory | 
Configurations
                    History
                    22 Apr 2025, 17:53
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:* | |
| First Time | Logpoint Logpoint siem | |
| References | () https://logpoint.com - Product | |
| References | () https://servicedesk.logpoint.com/hc/en-us/articles/18435146614301-Username-Enumeration-on-Shared-Widgets - Vendor Advisory | 
Information
                Published : 2024-05-01 18:15
Updated : 2025-04-22 17:53
NVD link : CVE-2024-30176
Mitre link : CVE-2024-30176
CVE.ORG link : CVE-2024-30176
JSON object : View
Products Affected
                logpoint
- siem
CWE
                
                    
                        
                        CWE-203
                        
            Observable Discrepancy
