CVE-2017-15110

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
References
Link Resource
http://www.securityfocus.com/bid/101909 Third Party Advisory VDB Entry
https://moodle.org/mod/forum/discuss.php?d=361784 Issue Tracking Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-20 14:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-15110

Mitre link : CVE-2017-15110

CVE.ORG link : CVE-2017-15110


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor