VulnerabilityModified
CVE-2012-1169
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
MEDIUM 5.3EPSS 1.78%
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- moodle/moodle · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.htmlThird Party Advisory
- https://access.redhat.com/security/cve/cve-2012-1169Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1169Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=198625Patch, Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-1169Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.htmlThird Party Advisory
- https://access.redhat.com/security/cve/cve-2012-1169Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1169Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=198625Patch, Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-1169Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.