Impact
docuForm GmbH FSM Client 11.11c contains a flaw in the login.php authentication routine that allows a remote attacker to observe differences in server responses for valid versus invalid usernames, thereby enabling user enumeration. The weakness, classified as CWE‑203, permits the attacker to discover existing account names and can aid in further attacks such as credential stuffing or brute‑force attempts, effectively compromising user confidentiality.
Affected Systems
All deployments of docuForm GmbH FSM Client 11.11c that expose the login.php endpoint over a network are affected. If the web interface is publicly reachable, the vulnerability applies to any instance using this version.
Risk and Exploitability
The flaw is accessed via a remote web interface, requiring only network connectivity to the affected server. With a CVSS score of 7.5 and an EPSS score of < 1%, the likelihood of exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog, so no publicly known exploit exists. Nonetheless, an attacker can use the enumeration capability as a stepping stone to further compromise user accounts or downstream services.
OpenCVE Enrichment