Executive brief
DernekPlus Website Template is a templating system used for website development. A flaw in the template allows attackers to determine whether valid user accounts exist through observable differences in server responses, enabling account enumeration attacks that could facilitate targeted phishing or credential-based attacks.
Technical details
This is an information disclosure vulnerability classified as an observable response discrepancy (timing attack variant). The vulnerable component is the DernekPlus Website Template authentication or user lookup mechanism, which leaks information about user account existence through detectable differences in HTTP response times, error messages, or response patterns. The attack requires network access to the affected website and no authentication is necessary—an unauthenticated attacker can enumerate valid accounts by submitting various usernames and analyzing responses. This enables account footprinting, a reconnaissance technique that feeds into social engineering or credential stuffing campaigns. No patch information is publicly available; the vendor was contacted but did not respond.
Affected products
- DernekPlus Website Template through 10092026
Timeline
- 2026-09-10: disclosed