Lucene search

K
osvGoogleOSV:GHSA-FC5P-VJ3H-X7G4
HistoryMay 13, 2022 - 1:12 a.m.

Moodle allows attackers to obtain sensitive information

2022-05-1301:12:50
Google
osv.dev
4

5.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.2%

The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.

5.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.2%