Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4532
HistoryJul 05, 2017 - 8:04 a.m.

Information Disclosure

2017-07-0508:04:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

EPSS

0.003

Percentile

69.1%

Moodle is vulnerable to information disclosure. The attack exists because notes/index.php and user/edit.php does not check for permission for access to certain pages. This allows a malicious user to obtain sensitive information such as account username and course information through a modified URL.