Description
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Remediation
References
Related Vulnerabilities
WordPress Plugin Malware Scanner Privilege Escalation (4.7.2)
Moodle Improper Input Validation Vulnerability (CVE-2018-1137)
WordPress Plugin Newsletter-Send awesome emails from WordPress Multiple Vulnerabilities (6.8.1)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1892)
Oracle Application Server CVE-2010-0067 Vulnerability (CVE-2010-0067)