Vulnerability Name: | CVE-2021-32477 (CCN-221922) | ||||||||||||
Assigned: | 2021-05-17 | ||||||||||||
Published: | 2021-05-17 | ||||||||||||
Updated: | 2022-07-02 | ||||||||||||
Summary: | The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | ||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-862 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-32477 Source: XF Type: UNKNOWN moodle-cve202132477-info-disc(221922) Source: CCN Type: Moodle Security Advisory MSA-21-0017 Last app access time is visible to non-site-admins on user profile page Source: MISC Type: Patch, Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=422313 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |