CVE-2011-4289: Infoleak
Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4289?
CVE-2011-4289 has been rated as a medium severity vulnerability due to its potential exposure of sensitive user information.
How do I fix CVE-2011-4289?
To fix CVE-2011-4289, upgrade Moodle to version 2.0.3 or later where the configuration setting issue is resolved.
What versions of Moodle are affected by CVE-2011-4289?
CVE-2011-4289 affects Moodle versions 2.0.0 to 2.0.2.
What type of vulnerability is CVE-2011-4289?
CVE-2011-4289 is a disclosure vulnerability that allows remote authenticated users to access sensitive information.
Is it safe to use Moodle versions prior to 2.0.3 after the discovery of CVE-2011-4289?
Using Moodle versions prior to 2.0.3 is not safe as they are susceptible to the vulnerability allowing exposure of email addresses.