← Back

CVE-2012-2353

nvd nist
Published: Jul 21, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

Affected (9)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Version 2.1.0
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Version 2.2.0
Version 2.2.1
Version 2.2.2

Timeline

No history available yet.