A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cq5f-wv7p-5gfc Moodle leaks user names
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Nov 2024 00:15:00 +0900

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
CPEs cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Vendors & Products Moodle
Moodle moodle

Tue, 19 Nov 2024 00:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 20:30:00 +0900

Type Values Removed Values Added
Description A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
Title Moodle: users' names returned in messaging error message
Weaknesses CWE-209
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-11-18T11:13:10.346Z

Reserved: 2024-10-09T12:15:07.577Z

Link: CVE-2024-48896

cve-icon Vulnrichment

Updated: 2024-11-18T14:58:24.404Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-18T12:15:18.093

Modified: 2024-11-20T14:47:12.777

Link: CVE-2024-48896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses