Vulnerability Name: | CVE-2017-15110 (CCN-135195) | ||||||||||||||||||||
Assigned: | 2017-11-20 | ||||||||||||||||||||
Published: | 2017-11-20 | ||||||||||||||||||||
Updated: | 2017-12-06 | ||||||||||||||||||||
Summary: | In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students. | ||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-15110 Source: BID Type: Third Party Advisory, VDB Entry 101909 Source: CCN Type: BID-101909 Moodle CVE-2017-15110 Information Disclosure Vulnerability Source: XF Type: UNKNOWN moodle-cve201715110-info-disc(135195) Source: CCN Type: Moodle Security Advisory MSA-17-0021 Students can find out email addresses of other students in the same course Source: CONFIRM Type: Issue Tracking, Mitigation, Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=361784 Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-15110 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |