Executive brief
Sage DPW, an HR and payroll software solution, contains a flaw in its login system that reveals whether a username is valid or not. By observing different error messages for existing versus non-existent accounts, an unauthorized person could compile a list of valid employee usernames. This information can be used to launch more targeted cyberattacks, such as password guessing or phishing campaigns.
Technical details
An observable response discrepancy (CWE-204) exists in the authentication handler of Sage DPW. The application returns different feedback or error messages depending on whether a submitted username exists in the database. A remote, unauthenticated attacker can exploit this behavior by programmatically submitting lists of potential usernames and analyzing the responses to identify valid accounts. This vulnerability was addressed in version 2021_06_004, where on-premise administrators were also given the ability to toggle this behavior. Sage DPW Cloud is reportedly unaffected.
Affected products
- Sage DPW Prior to 2021_06_004
Timeline
- 2026-03-24: disclosed: Vulnerability details shared via Pastebin by Limes Security.
- 2026-04-01: advisory: CVE published.