PT-2016-5034 · Moodle · Moodle
Roger
·
Published
2016-03-25
·
Updated
2022-05-13
·
CVE-2016-2154
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 2.8.x through 2.8.10
Moodle versions 2.9.x through 2.9.4
Moodle versions 3.0.x through 3.0.2
Description
The issue allows remote authenticated users to discover hidden course names by subscribing to a rule, due to the failure of the admin/tool/monitor/lib.php script in Event Monitor to consider the moodle/course:viewhiddencourses capability.
Recommendations
For Moodle versions 2.8.x through 2.8.10, update to version 2.8.11 or later.
For Moodle versions 2.9.x through 2.9.4, update to version 2.9.5 or later.
For Moodle versions 3.0.x through 3.0.2, update to version 3.0.3 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle