CVE-2012-1169

MEDIUM

Moodle < 2.2.2 - Unauthorized Personal Information Exposure via Page Breadcrumbs

Title source: llm
STIX 2.1

Description

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.

References (9)

Core 9
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2012-1169
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1169
Patch, Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=198625

Scores

CVSS v3 5.3
EPSS 0.0099
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
fedoraproject/fedora 15
fedoraproject/fedora 16
fedoraproject/fedora 17
moodle/moodle < 2.2.2
Published Nov 14, 2019
Tracked Since Feb 18, 2026