Description
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2189 | The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10. |
Github GHSA |
GHSA-c7v4-m269-4995 | Exposure of Sensitive Information to an Unauthorized Actor in Moodle |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.815Z
Reserved: 2020-09-16T00:00:00.000Z
Link: CVE-2020-25703
No data.
Status : Modified
Published: 2020-11-19T17:15:13.060
Modified: 2024-11-21T05:18:31.407
Link: CVE-2020-25703
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA