Full Disclosure mailing list archives

User Enumeration in IServ Schoolserver Web Login


From: naphthalin via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 9 Sep 2025 14:04:32 +0200

“I know where your children go to school.”
The web front end of the IServ school server from IServ GmbH allows user enumeration. Responses during failed login attempts differ, depending on if the user account exists, does not exist and other conditions. While this does not pose a security risk in many applications, it has to be considered extremely problematic in software designed for schools. Due to the widespread use of IServ in Germany, it would be possible to find out a child's school based on their first and last name, provided that the school uses IServ.

Particularly noteworthy threat scenarios include enumeration by perpetrators of domestic violence, by groups involved in cybergrooming and sextortion (such as the “764” gang), or targeting of children of particularly exposed individuals.

The manufacturer was contacted and stated that they do not interpret the issue as a vulnerability. There also appear to be no concerns regarding data protection and GDPR compliance. They further confirm that enumeration would also be possible via other interfaces and they do not intend to provide a fix.

Disclosure Timeline:
08.09.2025 - Vulnerability identified
08.09.2025 - Vendor notified
08.09.2025 - Vulnerability disputed by vendor
09.09.2025 - Public Disclosure
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread: