trixbox is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
trixbox 2.8.0.4 is vulnerable; other versions may also be affected.
Vendor Status:
Currently we are not aware of any vendor-supplied patches