在 Moodle 中发现了一个漏洞。用户列表过滤器未能正确执行对用户个人资料字段的可见性限制。拥有管理员权限的授权用户可以通过使用其无权直接查看的个人资料属性来过滤用户列表,从而通过推断隐藏的用户数据导致未授权的信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 5.2.0 ~ 5.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet