Prior to authentication, an attacker can leverage the action parameter handling in core/modules.php .