What is CVE-2025-13736?
When Multi-Attribute Login is enabled, the login interface inconsistently masks the existence of user accounts by revealing canonical usernames for valid users while echoing input for non-existent ones. This User Enumeration vulnerability could assist attackers in identifying valid accounts. It is recommended to disable the feature or apply the official patch to mitigate the risk.
Azərbaycanca: Bu boşluq Multi-Attribute Login funksiyası aktiv olduqda, giriş interfeysinin istifadəçi hesablarının mövcudluğunu ardıcıl şəkildə gizlədə bilməməsinə səbəb olur. Bu, təcavüzkara sistemdə etibarlı istifadəçi adlarını müəyyən etməyə imkan verə bilər. Təsirə məruz qalmamaq üçün bu funksiyanı deaktiv etmək və ya rəsmi yama tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What measures should be taken to protect against CVE-2025-13736?
It is recommended to disable the Multi-Attribute Login feature or apply the official patch to mitigate the risk.
What can an attacker gain by exploiting CVE-2025-13736?
This User Enumeration vulnerability could assist attackers in identifying valid user accounts on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.