CVE-2016-3731

MEDIUM

Moodle <3.0.3, <2.9.5, <2.8.11 - Info Disclosure

Title source: llm
STIX 2.1

Description

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/17/4
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1335933
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035902

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (22)
moodle/moodle 2.8.0
moodle/moodle 2.8.1
moodle/moodle 2.8.2
moodle/moodle 2.8.3
moodle/moodle 2.8.4
moodle/moodle 2.8.5
moodle/moodle 2.8.6
moodle/moodle 2.8.7
moodle/moodle 2.8.8
moodle/moodle 2.8.9
... and 12 more
Published Apr 20, 2017
Tracked Since Feb 18, 2026