VulnerabilityModified
CVE-2017-15110
This allows enumerating and guessing emails of other students.
MEDIUM 4.3EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/101909Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=361784Issue Tracking, Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/101909Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=361784Issue Tracking, Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.