LOW
Moodle: Multiple security fixes in 1.8.12 upstream release
Published Apr 29, 2010
1.3
LOWCVSS 4.0
EPSS 1.52%
Description
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
Affected products
No data.
OR
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.8.7
- 1.8.8
- 1.8.9
- 1.8.10
- 1.8.11
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.9.5
- 1.9.6
- 1.9.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&r2=1.168.2.29 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSE
- http://moodle.org/security x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1617 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=578811 Issue Tracking
- https://github.com/advisories/GHSA-q53j-c866-h9mw Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-1617
- https://www.cve.org/CVERecord?id=CVE-2010-1617
| Link | Providers | Tags |
|---|---|---|
| http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&r2=1.168.2.29 | x_refsource_CONFIRM | |
| http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html | vendor-advisoryx_refsource_SUSE | |
| http://moodle.org/security | x_refsource_CONFIRM | |
| http://www.vupen.com/english/advisories/2010/1107 | vdb-entryx_refsource_VUPEN | |
| https://access.redhat.com/security/cve/CVE-2010-1617 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=578811 | Issue Tracking | |
| https://github.com/advisories/GHSA-q53j-c866-h9mw | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-1617 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-1617 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2010
Updated Aug 7, 2024
Reserved Apr 29, 2010
Link CVE-2010-1617
CISA Vulnrichment
GHSA-Q53J-C866-H9MW Updated n/a