PT-2017-12372 · Moodle · Moodle
Juan Leyva
·
Published
2017-09-18
·
Updated
2022-05-17
·
CVE-2017-12157
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 3.x
Description
The issue allows teachers to view details about users in groups they cannot access through various course reports.
Recommendations
For Moodle versions 3.x, update to a version where this issue is resolved, or consider restricting access to sensitive course reports until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle