Description
Authenticated users were able to enumerate other users' names via the learning plans page.
Remediation
References
Related Vulnerabilities
WordPress Plugin Team Members Cross-Site Scripting (5.0.3)
MySQL CVE-2022-21316 Vulnerability (CVE-2022-21316)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4224)
MySQL CVE-2013-3812 Vulnerability (CVE-2013-3812)
WordPress Plugin Photo Gallery by Ays-Responsive Image Gallery SQL Injection (4.4.3)