The participants table download in Moodle always included user emails, but should have only done so when users emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 3.7.0 (including) | 3.7.8 (including) |
Moodle | Moodle | 3.8.0 (including) | 3.8.5 (including) |
Moodle | Moodle | 3.9.0 (including) | 3.9.2 (including) |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | xenial | * |