Email Address Enumeration Vulnerability in Moodle by Moodle Pty Ltd
CVE-2017-15110

4.3MEDIUM

Key Information:

Vendor
Moodle
Vendor
CVE Published:
20 November 2017

Summary

In Moodle versions 3.x, a vulnerability exists that enables students to discover the email addresses of other participants enrolled in the same course. Through the search functionality on the Participants page, students can access email addresses irrespective of the defined email visibility settings. This flaw allows for unauthorized email enumeration, potentially compromising student privacy and security.

Affected Version(s)

Moodle 3.x Moodle 3.x

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.