2024-12-08 03:06:42 +00:00

154 lines
4.8 KiB
JSON

{
"id": "CVE-2017-15110",
"sourceIdentifier": "secalert@redhat.com",
"published": "2017-11-20T14:29:00.247",
"lastModified": "2024-11-21T03:14:05.540",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students."
},
{
"lang": "es",
"value": "En las versiones 3.x de Moodle, los estudiantes pueden averiguar las direcciones de correo electr\u00f3nico de otros estudiantes en el mismo curso. Empleando la b\u00fasqueda en la p\u00e1gina Participants, los estudiantes podr\u00edan buscar las direcciones de correo electr\u00f3nico de todos los participantes, independientemente de la visibilidad del correo electr\u00f3nico. Esto permite la enumeraci\u00f3n y la adivinaci\u00f3n de correos electr\u00f3nicos de otros estudiantes."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"baseScore": 4.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"versionEndIncluding": "3.0.10",
"matchCriteriaId": "AEE2C318-E06D-4270-836A-48F07562EE3A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.1",
"versionEndIncluding": "3.1.8",
"matchCriteriaId": "83BC3C5B-EDCF-4838-B271-715E37F4ED3D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.2",
"versionEndIncluding": "3.2.5",
"matchCriteriaId": "C7325E47-944C-4D40-B679-28CD6EDD64BF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
"versionStartIncluding": "3.3",
"versionEndIncluding": "3.3.2",
"matchCriteriaId": "6303BBDF-8425-4BA5-981A-0553CAA88106"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/101909",
"source": "secalert@redhat.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://moodle.org/mod/forum/discuss.php?d=361784",
"source": "secalert@redhat.com",
"tags": [
"Issue Tracking",
"Mitigation",
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/101909",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://moodle.org/mod/forum/discuss.php?d=361784",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Mitigation",
"Vendor Advisory"
]
}
]
}