Description
membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.
Remediation
References
Related Vulnerabilities
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2018-7201)
WordPress Plugin Push Notifications for WordPress (Lite) Cross-Site Request Forgery (6.0)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2016-0219)
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Request Forgery (1.3.3)