Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-3170 - Vulnerability Database

Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-3170

Medium
Reference: CVE-2016-3170
Title: Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

The quothave you forgotten your passwordquot links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.