CVE-2020-9389: Squaredup
Low severity, CVSS 3.7. EPSS: 0.9% chance of exploitation in the next 30 days.
A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.
Affected products
- Squaredup Squaredup: up to and including 4.6
Published 2021-02-03. Last modified 2026-06-17.