CVE-2025-9031
Timing-Based Username Enumeration in DivvyDrive Information Technologies' DivvyDrive Web
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
13th
Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Domain Search Timing. This issue affects DivvyDrive Web: from 4.8.2.2 before 4.8.2.15.
| CWE | CWE-208 CWE-203 |
| Vendor | divvydrive information technologies inc. |
| Product | divvydrive web |
| Published | Sep 24, 2025 |
| Last Updated | Jun 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for divvydrive information technologies inc. divvydrive web
Be the first to know when new medium vulnerabilities affecting divvydrive information technologies inc. divvydrive web are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
DivvyDrive Information Technologies Inc. / DivvyDrive Web
4.8.2.2 < 4.8.2.15
References
Credits
Emre AKTAΕ