Discovered by Edward Prior on behalf of The Missing Link Security
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
Discovered in: 19.0
Fixed In: 19.0 minor release