Vulnerability Name: | CVE-2010-1617 (CCN-57551) |
Assigned: | 2010-04-06 |
Published: | 2010-04-06 |
Updated: | 2020-12-01 |
Summary: | user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-264
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2010-1617
Source: CONFIRM Type: UNKNOWN http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&r2=1.168.2.29
Source: SUSE Type: UNKNOWN SUSE-SR:2010:011
Source: CCN Type: MSA-10-0003 Disclosure of full user names
Source: CONFIRM Type: UNKNOWN http://moodle.org/security/
Source: DEBIAN Type: DSA-2115 moodle -- several vulnerabilities
Source: CCN Type: OSVDB ID: 64323 Moodle user/view.php Course Profile Page Username Disclosure
Source: CCN Type: BID-39150 Moodle Prior to 1.9.8/1.8.12 Multiple Vulnerabilities
Source: VUPEN Type: UNKNOWN ADV-2010-1107
Source: XF Type: UNKNOWN moodle-course-info-disc(57551)
Source: SUSE Type: SUSE-SR:2010:011 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:1.8.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.1:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.4:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.5:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.2:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.9:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.11:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.9.7:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:moodle:moodle:1.9.7:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:1.8.11:*:*:*:*:*:*:*AND cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |