Description
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Plugin:Newsletter 'data' Parameter Information Disclosure (1.5)
Werkzeug WSGI Improper Handling of Windows Device Names Vulnerability (CVE-2026-21860)
WordPress Plugin betterAmazonAPI Cross-Site Scripting (1.2)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11585)