Moodle doesn't properly check role
Low severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Package
Affected versions
>= 1.8.0, < 1.8.12
>= 1.9.0, < 1.9.8
Patched versions
1.8.12
1.9.8
Description
Published by the National Vulnerability Database
Apr 29, 2010
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 12, 2025
Last updated
Apr 12, 2025
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.
References