A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
History

Wed, 20 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle

Mon, 18 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
Title Moodle: users' names returned in messaging error message
Weaknesses CWE-209
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-11-18T11:13:10.346Z

Updated: 2024-11-18T11:13:10.346Z

Reserved: 2024-10-09T12:15:07.577Z

Link: CVE-2024-48896

cve-icon Vulnrichment

Updated: 2024-11-18T14:58:24.404Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T12:15:18.093

Modified: 2024-11-20T14:47:12.777

Link: CVE-2024-48896

cve-icon Redhat

No data.