Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-07-21T01:00:00

Updated: 2024-08-06T19:34:25.252Z

Reserved: 2012-04-19T00:00:00

Link: CVE-2012-2353

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-07-21T03:38:55.767

Modified: 2020-12-01T14:43:58.053

Link: CVE-2012-2353

cve-icon Redhat

No data.