In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/101909 | Third Party Advisory VDB Entry |
https://moodle.org/mod/forum/discuss.php?d=361784 | Issue Tracking Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-11-20 14:29
Updated : 2024-02-04 19:29
NVD link : CVE-2017-15110
Mitre link : CVE-2017-15110
CVE.ORG link : CVE-2017-15110
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor