user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora | Fedoraproject | 17 (including) | 17 (including) |
Fedora | Fedoraproject | 18 (including) | 18 (including) |
Moodle | Ubuntu | artful | * |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | cosmic | * |
Moodle | Ubuntu | disco | * |
Moodle | Ubuntu | eoan | * |
Moodle | Ubuntu | esm-apps/bionic | * |
Moodle | Ubuntu | esm-apps/xenial | * |
Moodle | Ubuntu | hardy | * |
Moodle | Ubuntu | lucid | * |
Moodle | Ubuntu | oneiric | * |
Moodle | Ubuntu | precise | * |
Moodle | Ubuntu | quantal | * |
Moodle | Ubuntu | raring | * |
Moodle | Ubuntu | saucy | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | upstream | * |
Moodle | Ubuntu | utopic | * |
Moodle | Ubuntu | vivid | * |
Moodle | Ubuntu | wily | * |
Moodle | Ubuntu | xenial | * |
Moodle | Ubuntu | yakkety | * |
Moodle | Ubuntu | zesty | * |