#VU101808 Information disclosure in Moodle - CVE-2024-55645
Published: December 17, 2024
Moodle
moodle.org
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to the email change confirmation token is available via preference. A remote user or attacker with physical access to the system can obtain the token and use it later to verify the email change without having access to the mailbox.