
CVE-2024-55374
Redcap 14.3.13 is vulnerable to user enumeration because it returns distinct error messages depending on whether the user exists or not. This allows an attacker to send multiple HTTP authentication requests to perform brute-force attacks. Although a protection mechanism exists to mitigate this vector, the mechanism itself allows an attacker to infer the existence of a valid user in the application.