Description
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.
No analysis available yet.
Remediation
Vendor Solution
Upgrade Alma Blog to version 2.2.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16914 | User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response. |
References
History
Wed, 15 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alma
Alma alma Blog |
|
| CPEs | cpe:2.3:a:alma:alma_blog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alma
Alma alma Blog |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T15:12:00.863Z
Reserved: 2024-02-01T08:39:00.508Z
Link: CVE-2024-1145
Updated: 2024-08-02T15:11:54.665Z
Status : Analyzed
Published: 2024-03-19T12:15:08.177
Modified: 2025-10-15T18:04:19.183
Link: CVE-2024-1145
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD