Описание
Moodle allows attackers to obtain sensitive information
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0124
- https://github.com/moodle/moodle/commit/2978623cda4521773fe2d45e04bee76601de487f
- https://github.com/moodle/moodle/commit/ae0ec61180ec71cb5b158633b0a3523a7ca41a82
- https://github.com/moodle/moodle/commit/db4e2c4cd47d48ebf06424d942bf603a8fa94d97
- https://github.com/moodle/moodle/commit/dc8f55c30211efd6fac80386e5b3bffef31cca13
- https://moodle.org/mod/forum/discuss.php?d=256421
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43916
- http://openwall.com/lists/oss-security/2014/03/17/1
Пакеты
moodle/moodle
< 2.4.9
2.4.9
moodle/moodle
>= 2.5.0, < 2.5.5
2.5.5
moodle/moodle
>= 2.6.0, < 2.6.2
2.6.2
EPSS
CVE ID
Связанные уязвимости
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
The identity-reporting implementations in mod/forum/renderer.php and m ...
EPSS