Lucene search

K
osvGoogleOSV:GHSA-P5J7-26WJ-423J
HistoryMay 13, 2022 - 1:12 a.m.

Moodle allows discovery of an author's username

2022-05-1301:12:42
Google
osv.dev
9
moodle
forum_print_latest_discussions
bypassing
answer-posting
discovery
username
q&a forum

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

44.6%

The forum_print_latest_discussions function in mod/forum/lib.php in Moodle through 2.4.11, 2.5.x before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2 allows remote authenticated users to bypass the individual answer-posting requirement without the mod/forum:viewqandawithoutposting capability, and discover an author’s username, by leveraging the student role and visiting a Q&A forum.

References

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

44.6%