CVE-2012-6100: Medium severity moodle vulnerability
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6100?
CVE-2012-6100 is classified as a medium-severity vulnerability due to its potential exposure of sensitive user data.
How do I fix CVE-2012-6100?
To mitigate CVE-2012-6100, you should upgrade Moodle to versions 2.2.7, 2.3.4, or 2.4.1 or later.
What versions of Moodle are affected by CVE-2012-6100?
CVE-2012-6100 affects Moodle versions 2.2.0 through 2.2.6, 2.3.0 through 2.3.3, and 2.4.0.
What type of information can be exposed due to CVE-2012-6100?
CVE-2012-6100 allows remote authenticated users to discover hidden lastaccess values of other users.
Is user authentication required to exploit CVE-2012-6100?
Yes, exploitation of CVE-2012-6100 requires that the attacker is a remote authenticated user.