CVE-2012-1169: Infoleak
Published Nov 14, 2019
·Updated
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
Affected Software
5 affected components
debian/moodle
Moodle moodle<2.2.2
Fedoraproject Fedora=15
Fedoraproject Fedora=16
Fedoraproject Fedora=17
Remediation
Patch Available
Patch Available
Event History
Nov 14, 2019
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2012-1169?
The severity of CVE-2012-1169 is considered medium, primarily due to the risk of personal information disclosure.
2
How do I fix CVE-2012-1169?
To fix CVE-2012-1169, upgrade Moodle to version 2.2.2 or later.
3
What is the impact of CVE-2012-1169 on users?
The impact of CVE-2012-1169 is that full names can be exposed in page breadcrumbs when only first names are intended to be displayed.
4
Which versions of Moodle are affected by CVE-2012-1169?
CVE-2012-1169 affects Moodle versions prior to 2.2.2.
5
Is there a workaround for CVE-2012-1169?
A possible workaround for CVE-2012-1169 is to adjust the administrative settings to limit the display of full names until an upgrade can be performed.