Impact
MCO is vulnerable to user enumeration. When an attacker initiates a username reminder or password reset, the application returns distinct messages for existing and non‑existent accounts. This behavior allows the attacker to determine which usernames or email addresses belong to valid users, providing valuable reconnaissance data. The flaw is a case of vague or insufficient input validation that results in a disclosure weakness (CWE‑204).
Affected Systems
MyComplianceOffice MCO, confirmed to be affected on version 25.3.3.1, may also impact other releases. The vendor is unreachable, so until a fix or workaround is deployed, all deployments running this or earlier versions should treat the CVE as present.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact; while it does not allow direct data exfiltration or code execution, it provides attackers useful reconnaissance data. The EPSS score of < 1% signals a very low likelihood of exploitation in the wild, yet the exposed endpoints can be invoked by unauthenticated users and an attacker can enumerate accounts by submitting many generic usernames and comparing responses. The vulnerability is not listed in the CISA KEV catalog, but the trivial nature of the attack path makes it a concern for organizations that expose account recovery functionality without additional safeguards.
OpenCVE Enrichment