CVE-2009-4298

Moodle <1.8.11-1.9.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.

References (9)

Core 9
Core References
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3455
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37614
Patch, Vendor Advisory x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=139102
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37244

Scores

EPSS 0.0075
EPSS Percentile 73.3%

Details

CWE
CWE-200
Status published
Products (15)
moodle/moodle 1.8.1
moodle/moodle 1.8.2
moodle/moodle 1.8.3
moodle/moodle 1.8.4
moodle/moodle 1.8.5
moodle/moodle 1.8.7
moodle/moodle 1.8.8
moodle/moodle 1.8.9
moodle/moodle 1.8.10
moodle/moodle 1.9.1
... and 5 more
Published Dec 16, 2009
Tracked Since Feb 18, 2026