Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2353

Опубликовано: 21 июл. 2012
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.1.5:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:moodle:moodle:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00176
Низкий

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

debian
почти 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

github
около 3 лет назад

Moodle Exposes Sensitive User Information

EPSS

Процентиль: 40%
0.00176
Низкий

4 Medium

CVSS2

Дефекты

CWE-200