A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2318822 |
|
History
Wed, 20 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Mon, 18 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site. | |
| Title | Moodle: users' names returned in messaging error message | |
| Weaknesses | CWE-209 | |
| References |
|
Status: PUBLISHED
Assigner: redhat
Published: 2024-11-18T11:13:10.346Z
Updated: 2024-11-18T11:13:10.346Z
Reserved: 2024-10-09T12:15:07.577Z
Link: CVE-2024-48896
Updated: 2024-11-18T14:58:24.404Z
Status : Analyzed
Published: 2024-11-18T12:15:18.093
Modified: 2024-11-20T14:47:12.777
Link: CVE-2024-48896
No data.