Description
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Remediation
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-4721)
WordPress Plugin WordPress Download Manager Arbitrary File Upload (2.8.97)
MySQL CVE-2019-2910 Vulnerability (CVE-2019-2910)
WordPress Plugin Ultimate Responsive Image Slider Unspecified Vulnerability (3.3.2)