{"id":"CVE-2016-3170","aliases":["GHSA-pqv4-xgqh-j8vh"],"url":"https://o3.security/vulnerability/CVE-2016-3170","summary":"Drupal sensitive information disclosure","details":"The \"have you forgotten your password\" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.","published":"2016-04-12T15:59:07.917Z","modified":"2026-07-08T05:49:08.228224338Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"7.43"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.0.4"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.0.4"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"7.43"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/02/24/19"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/03/15/10"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3498"},{"type":"FIX","url":"https://www.drupal.org/SA-CORE-2016-001"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:49:08.228224338Z"}}