Impact
Observable differences in the HTTP responses of the GastroMenum Web Panel expose the existence of user accounts, enabling attackers to perform account footprinting. The vulnerability arises from insufficient validation of query parameters that determine whether an account exists. Successful exploitation allows an attacker to enumerate valid usernames, thereby facilitating targeted credential‑guessing or social‑engineering campaigns, which can compromise confidentiality of user identities and potential access to sensitive resources.
Affected Systems
All installations of GastroMenum Web Panel with versions prior to 31.08.2026 are affected. The vulnerability is documented for the product line managed by GastroMenum, and no earlier patch versions have mitigated this flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The exploit probability is not quantified in the EPSS data, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be remote, reachable via the publicly exposed web interface. Because the weakness falls under CWE-204, attackers gain sensitive information through reference handling in the application. No additional exploitation prerequisites are described, implying that an unauthenticated client can trigger the enumeration by observing response differences.
OpenCVE Enrichment