CVE-2017-15110

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
20/11/2017
Last modified:
20/04/2025

Description

In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.0.10 (including)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.1 (including) 3.1.8 (including)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.2 (including) 3.2.5 (including)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.3 (including) 3.3.2 (including)