Impact
The flaw in Moodle permits an authorized user with manager permissions to apply filters to user lists based on profile attributes that the user is not allowed to view directly. By manipulating the filter, the attacker can deduce the values of hidden profile fields, effectively revealing private information that should have remained hidden. This behavior violates the intended visibility restrictions and results in an information disclosure vulnerability.
Affected Systems
The vulnerability affects all Moodle deployments in which the default user visibility settings are in place. No specific version numbers are listed, so any installation that has not applied the latest security updates could be impacted.
Risk and Exploitability
The CVSS score of 2.7 reflects a low impact severity. Exploitation requires an authenticated user with manager-level privileges and is not possible from an unauthenticated perspective. EPSS data is not available, and the issue is not cataloged in CISA KEV, suggesting a limited current exploitation risk. Nevertheless, the confidentiality of user data is compromised when the attacker can infer values that are otherwise invisible.
OpenCVE Enrichment