4.3
CVE-2026-102579
- EPSS 0.22%
- Veröffentlicht 30.09.2026 08:36:04
- Zuletzt bearbeitet 01.10.2026 14:21:12
- Erkennungen
Moodle: user profile information disclosure via grade web service
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to view. This issue leads to unauthorized information disclosure.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.11 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| patrick@puiterwijk.org | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.
https://moodle.org/mod/forum/discuss.php?d=482497
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-89381
https://access.redhat.com/security/cve/CVE-2026-102579
https://bugzilla.redhat.com/show_bug.cgi?id=2543633