MEDIUM
enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL
Published May 27, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.88%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.