VulnerabilityModified
CVE-2011-4304
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
MEDIUM 4.0EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=d0157d827bc254ba386a5e5b41b13be2698ee76e
- http://moodle.org/mod/forum/discuss.php?d=188316Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=747444Patch
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=d0157d827bc254ba386a5e5b41b13be2698ee76e
- http://moodle.org/mod/forum/discuss.php?d=188316Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=747444Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.