4.3
CVSSv2

CVE-2014-0217

Published: 27/05/2014 Updated: 01/12/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

enrol/index.php in Moodle 2.6.x prior to 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote malicious users to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.6.2

moodle moodle 2.6.0

moodle moodle 2.6.1