Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qg4-2fcm-c8f9

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 4.9

Описание

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.3

2.0.3

EPSS

Процентиль: 42%
0.00199
Низкий

4.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 13 лет назад

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

nvd
почти 13 лет назад

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

debian
почти 13 лет назад

Moodle 2.0.x before 2.0.3 does not recognize the configuration setting ...

EPSS

Процентиль: 42%
0.00199
Низкий

4.9 Medium

CVSS4

Дефекты

CWE-200