In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
References
Link | Resource |
---|---|
https://moodle.org/mod/forum/discuss.php?d=361784 | Issue Tracking Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/101909 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-11-20 06:29
Updated : 2017-12-06 06:27
NVD link : CVE-2017-15110
Mitre link : CVE-2017-15110
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
moodle
- moodle