CVE-2011-4593: Infoleak
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/actionredir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4593?
CVE-2011-4593 has been classified as a medium severity vulnerability due to its potential to expose email addresses to unauthorized users.
How do I fix CVE-2011-4593?
To fix CVE-2011-4593, upgrade your Moodle installation to version 1.9.15, 2.0.6, or 2.1.3 or later.
Who is affected by CVE-2011-4593?
CVE-2011-4593 affects users of Moodle versions prior to 1.9.15, 2.0.6, and 2.1.3.
What is the impact of CVE-2011-4593?
The impact of CVE-2011-4593 allows remote authenticated users to discover email addresses via the messaging interface.
Is there a workaround for CVE-2011-4593?
There are no specific workarounds for CVE-2011-4593, so updating to a patched version is the best approach.