Vulnerability Bulletins

MSA-17-0021: Students can find out email addresses of other students in the same course


System information

   
Affected software PHP

Description

by Marina Glancy. Using search on Participants page students could search email addresses of all participants regardless of email visibility. This allows to enumerate and guess emails of other studentsSeverity/Risk:MinorVersions affected:3.3 to 3.3.2, 3.2 to 3.2.5, 3.1 to 3.1.8 and earlier unsupported versionsVersions fixed:3.4, 3.3.3, 3.2.6 and 3.1.9Reported by:Tim SchroederWorkaround:Prohibit capability moodle/course:viewparticipants (View participants) for Student role until Moodle is

More info:

https://moodle.org/mod/forum/discuss.php?d=361784&parent=1458930

Standar resources

Property Value
CVE CVE-2017-1511.

Version history

Version Comments Date
1.0 Advisory issued 2017-11-20
Ministerio de Defensa
CNI
CCN
CCN-CERT