#VU39159 Information disclosure in Moodle - CVE-2016-3731

 

#VU39159 Information disclosure in Moodle - CVE-2016-3731

Published: April 21, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39159
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-3731
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Moodle
Software vendor:
moodle.org

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.


Remediation

Install update from vendor's website.

External links