Description
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Remediation
References
Related Vulnerabilities
WordPress Plugin The Events Calendar Cross-Site Scripting (3.0)
ProjectSend Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2017-20101)
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more PHAR Deserialization (2.9.8.5)
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281)