An issue in the component routeuser.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21493
Reference (s):
- https://gitee.com/xiuno/xiunobbs/issues/I1690W
- https://github.com/wanghaiwei/xiuno-docker/issues/3

