Description
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4618 | Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section. |
Github GHSA |
GHSA-mr97-gvvg-rhgh | Moodle Exposes Sensitive User Information |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T19:34:25.252Z
Reserved: 2012-04-19T00:00:00.000Z
Link: CVE-2012-2353
No data.
Status : Deferred
Published: 2012-07-21T03:38:55.767
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-2353
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA