CVE-2020-25703: Infoleak
The participants table download always included user emails, but should have only done so when users' emails are not hidden.
Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8
Other sources
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25703?
CVE-2020-25703 is classified as a medium severity vulnerability.
How do I fix CVE-2020-25703?
To fix CVE-2020-25703, upgrade to Moodle version 3.9.3, 3.8.6, or 3.7.9, or later.
What versions are affected by CVE-2020-25703?
CVE-2020-25703 affects Moodle versions 3.9 to 3.9.2, 3.8 to 3.8.5, and 3.7 to 3.7.8.
What type of information does CVE-2020-25703 expose?
CVE-2020-25703 exposes user emails in the participants table download despite the privacy settings.
Is CVE-2020-25703 a privacy-related vulnerability?
Yes, CVE-2020-25703 is a privacy-related vulnerability because it improperly exposes user emails.