Full Disclosure mailing list archives
User Enumeration in IServ Schoolserver Web Login
From: naphthalin via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 9 Sep 2025 14:04:32 +0200
“I know where your children go to school.”The web front end of the IServ school server from IServ GmbH allows user enumeration. Responses during failed login attempts differ, depending on if the user account exists, does not exist and other conditions. While this does not pose a security risk in many applications, it has to be considered extremely problematic in software designed for schools. Due to the widespread use of IServ in Germany, it would be possible to find out a child's school based on their first and last name, provided that the school uses IServ.
Particularly noteworthy threat scenarios include enumeration by perpetrators of domestic violence, by groups involved in cybergrooming and sextortion (such as the “764” gang), or targeting of children of particularly exposed individuals.
The manufacturer was contacted and stated that they do not interpret the issue as a vulnerability. There also appear to be no concerns regarding data protection and GDPR compliance. They further confirm that enumeration would also be possible via other interfaces and they do not intend to provide a fix.
Disclosure Timeline: 08.09.2025 - Vulnerability identified 08.09.2025 - Vendor notified 08.09.2025 - Vulnerability disputed by vendor 09.09.2025 - Public Disclosure _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- User Enumeration in IServ Schoolserver Web Login naphthalin via Fulldisclosure (Sep 10)
