CVE-2021-20281

MEDIUM

moodle 3.5.0-3.5.16 and 3.10.0-3.10.1 - Exposure of Sensitive Information via Online Users Block

Title source: llm
STIX 2.1

Description

It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

References (4)

Core 4
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1939041
Patch, Vendor Advisory x_refsource_misc
https://moodle.org/mod/forum/discuss.php?d=419652

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-863
Status published
Products (4)
fedoraproject/fedora 32
fedoraproject/fedora 34
moodle/moodle 3.10.0 - 3.10.2Packagist
moodle/moodle 3.5.0 - 3.5.17
Published Mar 15, 2021
Tracked Since Feb 18, 2026