REDHAT-BUG-2543642: Low severity Moodle Moodle vulnerability
Published Sep 29, 2026
·Updated
A flaw was found in Moodle. User list filters did not respect user profile field visibility settings, allowing a manager to filter by a profile field they could not otherwise view on a user's profile, resulting in partial, inference-based information disclosure.
Affected Software
1 affected component
Moodle Moodle
Event History
Sep 29, 2026
Data Sourced
via Red Hat·08:37 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must have manager-level access that allows them to use user list filters. The disclosure occurs when they filter on a user profile field that is hidden from them on individual user profiles.
2
What information can be exposed?
The issue can reveal partial information through inference based on filter results. It does not indicate that the hidden profile field value is directly displayed.