Description
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given that is registered with a user then this error will not appear. A malicious actor could abuse this to enumerate the email addresses of
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-1737 Vulnerability (CVE-2012-1737)
Joomla Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2011-4912)
WordPress Plugin Job Manager Cross-Site Scripting (0.7.25)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502)