Impact
The vulnerability in Bilin Software’s HUMANIST Digital Human Resources allows an attacker to determine valid usernames by observing differences in login responses. The weakness is rooted in CWE‑204, where application logic exposes information through varying responses. A successful exploit provides an attacker with a list of existing accounts, potentially aiding subsequent credential‑guessing or social‑engineering attacks, and thereby compromising confidentiality of user data.
Affected Systems
Bilin Software and Informatics Consultancy Inc. offer the HUMANIST Digital Human Resources product. Versions from 26.0 through just before 26.1 are affected. Users operating these releases are potentially vulnerable to account enumeration.
Risk and Exploitability
With a CVSS score of 5.3 the risk is moderate; the EPSS score is not available, and KEV does not list this CVE. The likely attack vector is a network‑based, web‑application attack that exploits the login page. An attacker can send automated login requests to distinguish legitimate usernames from non‑existent ones based on response timing or content differences. The vulnerability requires no special privileges and can be triggered from any remote machine with network access to the application interface.
OpenCVE Enrichment