The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-12-16T01:00:00Z
Updated: 2024-09-17T03:02:42.821Z
Reserved: 2009-12-11T00:00:00Z
Link: CVE-2009-4298
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-12-16T01:30:00.327
Modified: 2024-11-21T01:09:18.637
Link: CVE-2009-4298
Redhat