Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-345q-9jmq-g9q4

Опубликовано: 25 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Moodle allows unauthenticated REST API user data exposure

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites where PHP is configured with zend.exception_ignore_args = 'On' or zend.exception_ignore_args = 1 in the relevant php.ini file are NOT affected by this vulnerability. Sites that do not have the zend.exception_ignore_args setting enabled and are using the internal Moodle LMS authentication system are affected by this vulnerability.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.3

4.5.3

EPSS

Процентиль: 25%
0.00083
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

CVSS3: 7.5
debian
около 2 месяцев назад

A flaw has been identified in Moodle where, on certain sites, unauthen ...

CVSS3: 7.5
redos
3 дня назад

Множественные уязвимости moodle

EPSS

Процентиль: 25%
0.00083
Низкий

7.5 High

CVSS3

Дефекты

CWE-200