Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102587— Moodle: user list filters bypass profile field visibility

Quick assessment

Affected
CVE-2026-102587
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Moodle 中发现了一个漏洞。用户列表过滤器未能正确执行对用户个人资料字段的可见性限制。拥有管理员权限的授权用户可以通过使用其无权直接查看的个人资料属性来过滤用户列表,从而通过推断隐藏的用户数据导致未授权的信息泄露。

CVSS 2.7 · Low EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 4

VendorProduct Version RangeStatus
None None 5.2.0< 5.2.2 affected
5.1.0< 5.1.6 affected
5.0.0< 5.0.9 affected
< 4.5.13 affected

I. Basic Information for CVE-2026-102587

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Moodle: user list filters bypass profile field visibility
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
响应差异性信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 5.2.0 ~ 5.2.2 -

II. Public POCs for CVE-2026-102587

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102587

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102587 (1)

Vendor Advisories for CVE-2026-102587 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102587

No comments yet


Leave a comment