A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email address is incorrect, but there is a different error message for invalid credentials with a correct email address.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NNicehash Miner
APPNicehash< 2.0.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-6120HIGH7.5same product
An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email...
CVE-2019-6121LOW3.7same product
Odkryto problem w NiceHash Miner przed wersją 2.0.3.0. Brakujące sprawdzenie autoryzacji pozwala atakującemu n...
CVE-2025-56513CRITICAL9.8PL ✓same vendor
RCE przez niezabezpieczony mechanizm aktualizacji w NiceHash QuickMiner