Description
login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14827 Vulnerability (CVE-2020-14827)
WordPress Plugin WPS Hide Login Cross-Site Request Forgery (1.0)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-6600)
MySQL CVE-2020-14845 Vulnerability (CVE-2020-14845)
Drupal Core 9.0.x Multiple Cross-Site Scripting Vulnerabilities (9.0.0 - 9.0.5)