Information disclosure in Moodle - CVE-2012-2353

 

Information disclosure in Moodle - CVE-2012-2353

Published: July 21, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43819
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2353
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-2353

Install update from vendor's website.

moodle - addressed in versions 1.9.19-1.el5, 1.9.19-2.el5, 1.9.19-3.el5, 2.1.6-1.el6, 2.1.7-1.el6

External References

Related Security Bulletins