Описание
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue TrackingMitigationVendor Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
In Moodle 3.x, students can find out email addresses of other students ...
Moodle Exposure of Sensitive Information to an Unauthorized Actor
EPSS
4.3 Medium
CVSS3
4 Medium
CVSS2