PT-2017-13873 · Moodle · Moodle
Tim Schroeder
·
Publicado
2017-11-20
·
Atualizado
2022-05-17
·
CVE-2017-15110
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 3.x
Description
The issue allows students to discover email addresses of other students in the same course by using the search function on the Participants page, regardless of the email visibility settings. This enables students to enumerate and guess emails of their peers.
Recommendations
For Moodle versions 3.x, restrict access to the Participants page search function to minimize the risk of email address enumeration. Consider implementing additional privacy settings to control the visibility of email addresses for course participants.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moodle