---
id: CVE-2018-25350
title: >-
  userSpice 4.3.24 contains a username enumeration vulnerability that allows
  unauthenticated attackers to discover valid usernames by sending POST requests
  to the existingUsernameCheck.php endpoint
summary: >-
  userSpice 4.3.24 contains a username enumeration vulnerability that allows
  unauthenticated attackers to discover valid usernames by sending POST requests
  to the existingUsernameCheck.php endpoint. Attackers can submit usernames and
  analy…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-204
published: '2026-05-23'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25350'
references:
  - url: 'https://www.exploit-db.com/exploits/44872'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/userspice-username-enumeration-via-existingusernamecheck-php
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00433
epssPercentile: 0.35493
ingestedAt: '2026-10-06T22:23:15.924Z'
---

## Overview

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
