Moodle allows discovery of an author's username
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2024
Package
Affected versions
< 2.5.8
>= 2.6.0, < 2.6.5
>= 2.7.0, < 2.7.2
Patched versions
2.5.8
2.6.5
2.7.2
Description
Published by the National Vulnerability Database
Sep 15, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 24, 2024
Last updated
Feb 2, 2024
The forum_print_latest_discussions function in mod/forum/lib.php in Moodle through 2.4.11, 2.5.x before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2 allows remote authenticated users to bypass the individual answer-posting requirement without the mod/forum:viewqandawithoutposting capability, and discover an author's username, by leveraging the student role and visiting a Q&A forum.
References