Information disclosure in Moodle - CVE-2012-0792
Published: July 17, 2012 / Updated: August 11, 2020
Vulnerability identifier: #VU43857
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0792
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to gain access to sensitive information.
mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2012-0792
Install update from vendor's website.
moodle - update to 2.1.4-1.el6