CVE-2014-0124: Moodle allows attackers to obtain sensitive information
(updated )
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
References
- git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43916
- openwall.com/lists/oss-security/2014/03/17/1
- github.com/advisories/GHSA-fc5p-vj3h-x7g4
- github.com/moodle/moodle/commit/2978623cda4521773fe2d45e04bee76601de487f
- github.com/moodle/moodle/commit/ae0ec61180ec71cb5b158633b0a3523a7ca41a82
- github.com/moodle/moodle/commit/db4e2c4cd47d48ebf06424d942bf603a8fa94d97
- github.com/moodle/moodle/commit/dc8f55c30211efd6fac80386e5b3bffef31cca13
- moodle.org/mod/forum/discuss.php?d=256421
- nvd.nist.gov/vuln/detail/CVE-2014-0124
Detect and mitigate CVE-2014-0124 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →