CVE-2012-2353: Infoleak
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2353?
CVE-2012-2353 has a moderate severity rating due to its potential for exposing sensitive user information.
How do I fix CVE-2012-2353?
To resolve CVE-2012-2353, upgrade Moodle to version 2.1.6 or higher for the 2.1.x series and 2.2.3 or higher for the 2.2.x series.
What type of vulnerability is CVE-2012-2353?
CVE-2012-2353 is a vulnerability that allows remote authenticated users to access sensitive information from hidden fields.
Which versions of Moodle are affected by CVE-2012-2353?
CVE-2012-2353 affects Moodle versions 2.1.0 to 2.1.5 and 2.2.0 to 2.2.2.
Who can exploit CVE-2012-2353?
CVE-2012-2353 can be exploited by remote authenticated users with the teacher role in Moodle.