Publish Advisories

GHSA-mr97-gvvg-rhgh
GHSA-mr97-gvvg-rhgh
This commit is contained in:
advisory-database[bot]
2024-01-12 16:22:26 +00:00
parent 7226031e32
commit 5f28525c97
2 changed files with 93 additions and 39 deletions
@@ -0,0 +1,93 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mr97-gvvg-rhgh",
"modified": "2024-01-12T16:20:31Z",
"published": "2022-05-13T01:13:06Z",
"aliases": [
"CVE-2012-2353"
],
"summary": "Moodle Exposes Sensitive User Information",
"details": "Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to \"Enrolled users\" under the Users Settings section.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.1"
},
{
"fixed": "2.1.6"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.2"
},
{
"fixed": "2.2.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-2353"
},
{
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/a645b79113b2ee7881b6bdae64a0c2a9f04db5c7"
},
{
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/ce13ea6ceb15f00c3cc6d40d79b06be39de7987a"
},
{
"type": "WEB",
"url": "https://github.com/moodle/moodle/commit/cfaa50a61d61719c65aa7e26f5444852931e07b6"
},
{
"type": "PACKAGE",
"url": "https://github.com/moodle/moodle"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31923"
},
{
"type": "WEB",
"url": "http://openwall.com/lists/oss-security/2012/05/23/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-12T16:20:31Z",
"nvd_published_at": "2012-07-21T03:38:00Z"
}
}
@@ -1,39 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mr97-gvvg-rhgh",
"modified": "2022-05-13T01:13:06Z",
"published": "2022-05-13T01:13:06Z",
"aliases": [
"CVE-2012-2353"
],
"details": "Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to \"Enrolled users\" under the Users Settings section.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-2353"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31923"
},
{
"type": "WEB",
"url": "http://openwall.com/lists/oss-security/2012/05/23/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-07-21T03:38:00Z"
}
}