Описание
Moodle doesn't properly check role
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
Пакеты
moodle/moodle
>= 1.8.0, < 1.8.12
1.8.12
moodle/moodle
>= 1.9.0, < 1.9.8
1.9.8
Связанные уязвимости
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 doe ...