Information disclosure in Moodle - CVE-2012-0792

 

Information disclosure in Moodle - CVE-2012-0792

Published: July 17, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43857
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0792
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-0792

Install update from vendor's website.

moodle - update to 2.1.4-1.el6

External References

Related Security Bulletins