In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
References
Link | Resource |
---|---|
https://moodle.org/mod/forum/discuss.php?d=358586 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/100848 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-17 21:29
Updated : 2017-09-28 11:15
NVD link : CVE-2017-12157
Mitre link : CVE-2017-12157
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
moodle
- moodle