Description
Authenticated users were able to enumerate other users' names via the learning plans page.
Remediation
References
Related Vulnerabilities
phpMyAdmin Improper Input Validation Vulnerability (CVE-2017-1000016)
WordPress Plugin WPGlobus Translate Options Cross-Site Scripting (2.1.0)
Jolokia Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-10899)
MySQL CVE-2020-2573 Vulnerability (CVE-2020-2573)
MongoDb Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6494)