Moodle does not enforce the forceloginforprofiles setting
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 19, 2024
Package
Affected versions
<= 2.1.10
>= 2.2.0, < 2.2.8
>= 2.3.0, < 2.3.5
>= 2.4.0, < 2.4.2
Patched versions
2.2.8
2.3.5
2.4.2
Description
Published by the National Vulnerability Database
Mar 25, 2013
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 19, 2024
Last updated
Jan 19, 2024
user/view.php
in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce theforceloginforprofiles
setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.References