Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html | third party advisory |
https://security-tracker.debian.org/tracker/CVE-2012-1169 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1169 | issue tracking third party advisory patch |
https://access.redhat.com/security/cve/cve-2012-1169 | broken link |
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html | third party advisory |
https://moodle.org/mod/forum/discuss.php?d=198625 | patch vendor advisory |