First published: Thu Nov 14 2019(Updated: )
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/moodle | ||
Moodle | <2.2.2 | |
Fedora | =15 | |
Fedora | =16 | |
Fedora | =17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-1169 is considered medium, primarily due to the risk of personal information disclosure.
To fix CVE-2012-1169, upgrade Moodle to version 2.2.2 or later.
The impact of CVE-2012-1169 is that full names can be exposed in page breadcrumbs when only first names are intended to be displayed.
CVE-2012-1169 affects Moodle versions prior to 2.2.2.
A possible workaround for CVE-2012-1169 is to adjust the administrative settings to limit the display of full names until an upgrade can be performed.